CVE-2024-12673
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
12/02/2025
Last modified:
12/02/2025
Description
An improper privilege vulnerability was reported in a BIOS customization feature of Lenovo Vantage on SMB notebook devices which could allow a local attacker to elevate privileges on the system.<br />
<br />
This vulnerability only affects Vantage installed on these devices:<br />
<br />
* Lenovo V Series (Gen 5)<br />
* ThinkBook 14 (Gen 6, 7)<br />
* ThinkBook 16 (Gen 6, 7)<br />
* ThinkPad E Series (Gen 1)
Impact
Base Score 4.0
8.50
Severity 4.0
HIGH
Base Score 3.x
7.80
Severity 3.x
HIGH



