CVE-2024-5474
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/10/2024
Last modified:
15/11/2024
Description
A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 that could allow a local attacker to read files on the system with elevated privileges during installation of the package. Previously installed versions are not affected by this issue.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:lenovo:dolby_vision_provisioning:*:*:*:*:*:*:*:* | 2.0.0.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page