CVE-2019-6149

Severity CVSS v4.0:
Pending analysis
Type:
CWE-428 Unquoted Search Path or Element
Publication date:
18/03/2019
Last modified:
21/03/2019

Description

An unquoted search path vulnerability was identified in Lenovo Dynamic Power Reduction Utility prior to version 2.2.2.0 that could allow a malicious user with local access to execute code with administrative privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lenovo:dynamic_power_reduction:*:*:*:*:*:*:*:* 2.2.2.0 (excluding)
cpe:2.3:h:lenovo:thinkpad_x1_carbon:-:*:*:*:*:*:*:*