A symbolic link vulnerability in some Lenovo installation packages, prior to version 1.2.9.3, could allow privileged file operations during file extraction and installation.
2020-06-09T20:15:11.787
2024-11-21T04:46:09.287
Modified
CVSSv3.1: 6.7 (MEDIUM)
AV:L/AC:M/Au:N/C:C/I:C/A:C
3.4
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | lenovo | installation_package | < 1.2.9.3 | Yes |