7.8

CVE-2021-3462

A privilege escalation vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that could allow unauthorized access to the driver's device object.

Data is provided by the National Vulnerability Database (NVD)
LenovoPower Management Driver SwPlatformwindows_10 Version < 1.67.17.54
   LenovoThinkpad 11e Gen 5 Version-
   LenovoThinkpad 11e Yoga Gen 6 Version-
   LenovoThinkpad 13 Gen 2 Version-
   LenovoThinkpad 25 Version-
   LenovoThinkpad A275 Version-
   LenovoThinkpad A285 Version-
   LenovoThinkpad A475 Version-
   LenovoThinkpad A485 Version-
   LenovoThinkpad E14 Version-
   LenovoThinkpad E14 Gen2 Version-
   LenovoThinkpad E15 Version-
   LenovoThinkpad E15 Gen2 Version-
   LenovoThinkpad E470 Version-
   LenovoThinkpad E470c Version-
   LenovoThinkpad E475 Version-
   LenovoThinkpad E480 Version-
   LenovoThinkpad E490 Version-
   LenovoThinkpad E495 Version-
   LenovoThinkpad E570 Version-
   LenovoThinkpad E570c Version-
   LenovoThinkpad E575 Version-
   LenovoThinkpad E580 Version-
   LenovoThinkpad E590 Version-
   LenovoThinkpad E595 Version-
   LenovoThinkpad L13 Version-
   LenovoThinkpad L13 Gen 1 Version-
   LenovoThinkpad L13 Gen 2 Version-
   LenovoThinkpad L13 Yoga Version-
   LenovoThinkpad L13 Yoga Gen 1 Version-
   LenovoThinkpad L13 Yoga Gen 2 Version-
   LenovoThinkpad L14 Gen 1 Version-
   LenovoThinkpad L14 Gen 2 Version-
   LenovoThinkpad L15 Gen 1 Version-
   LenovoThinkpad L15 Gen 2 Version-
   LenovoThinkpad L380 Version-
   LenovoThinkpad L380 Yoga Version-
   LenovoThinkpad L390 Version-
   LenovoThinkpad L390 Yoga Version-
   LenovoThinkpad L470 Version-
   LenovoThinkpad L480 Version-
   LenovoThinkpad L490 Version-
   LenovoThinkpad L570 Version-
   LenovoThinkpad L580 Version-
   LenovoThinkpad L590 Version-
   LenovoThinkpad P1 Version-
   LenovoThinkpad P1 Gen 2 Version-
   LenovoThinkpad P1 Gen 3 Version-
   LenovoThinkpad P14s Gen 1 Version-
   LenovoThinkpad P14s Gen 2 Version-
   LenovoThinkpad P15 Gen 1 Version-
   LenovoThinkpad P15s Gen 1 Version-
   LenovoThinkpad P15s Gen 2 Version-
   LenovoThinkpad P15v Gen 1 Version-
   LenovoThinkpad P17 Gen 1 Version-
   LenovoThinkpad P43s Version-
   LenovoThinkpad P51 Version-
   LenovoThinkpad P51s Version-
   LenovoThinkpad P52 Version-
   LenovoThinkpad P52s Version-
   LenovoThinkpad P53 Version-
   LenovoThinkpad P53s Version-
   LenovoThinkpad P71 Version-
   LenovoThinkpad P72 Version-
   LenovoThinkpad P73 Version-
   LenovoThinkpad R14 Version-
   LenovoThinkpad R14 Gen 2 Version-
   LenovoThinkpad R480 Version-
   LenovoThinkpad S1 Gen 4 Version-
   LenovoThinkpad S2 Gen 2 Version-
   LenovoThinkpad S2 Gen 5 Version-
   LenovoThinkpad S2 Gen 6 Version-
   LenovoThinkpad S2 Yoga Gen 5 Version-
   LenovoThinkpad S2 Yoga Gen 6 Version-
   LenovoThinkpad S3 Gen 2 Version-
   LenovoThinkpad S5 Gen 2 Version-
   LenovoThinkpad T14 Gen 1 Version-
   LenovoThinkpad T14 Gen 2 Version-
   LenovoThinkpad T14s Gen 1 Version-
   LenovoThinkpad T14s Gen 2i Version-
   LenovoThinkpad T15 Gen 1 Version-
   LenovoThinkpad T15 Gen 2 Version-
   LenovoThinkpad T15g Gen 1 Version-
   LenovoThinkpad T15p Gen 1 Version-
   LenovoThinkpad T470 Version-
   LenovoThinkpad T470p Version-
   LenovoThinkpad T470s Version-
   LenovoThinkpad T480 Version-
   LenovoThinkpad T480s Version-
   LenovoThinkpad T490 Version-
   LenovoThinkpad T490s Version-
   LenovoThinkpad T495 Version-
   LenovoThinkpad T570 Version-
   LenovoThinkpad T580 Version-
   LenovoThinkpad T590 Version-
   LenovoThinkpad X1 Carbon Gen 5 Version-
   LenovoThinkpad X1 Carbon Gen 6 Version-
   LenovoThinkpad X1 Carbon Gen 7 Version-
   LenovoThinkpad X1 Carbon Gen 8 Version-
   LenovoThinkpad X1 Carbon Gen 9 Version-
   LenovoThinkpad X1 Extreme Version-
   LenovoThinkpad X1 Extreme 2nd Version-
   LenovoThinkpad X1 Extreme Gen 3 Version-
   LenovoThinkpad X1 Nano Gen 1 Version-
   LenovoThinkpad X1 Tablet Gen 2 Version-
   LenovoThinkpad X1 Tablet Gen 3 Version-
   LenovoThinkpad X1 Titanium Gen 1 Version-
   LenovoThinkpad X1 Yoga Gen 2 Version-
   LenovoThinkpad X1 Yoga Gen 3 Version-
   LenovoThinkpad X1 Yoga Gen 4 Version-
   LenovoThinkpad X1 Yoga Gen 5 Version-
   LenovoThinkpad X1 Yoga Gen 6 Version-
   LenovoThinkpad X12 Version-
   LenovoThinkpad X13 Gen 1 Version-
   LenovoThinkpad X13 Gen 2i Version-
   LenovoThinkpad X13 Yoga Gen 1 Version-
   LenovoThinkpad X13 Yoga Gen 2 Version-
   LenovoThinkpad X270 Version-
   LenovoThinkpad X280 Version-
   LenovoThinkpad X380 Yoga Version-
   LenovoThinkpad X390 Version-
   LenovoThinkpad X390 Yoga Version-
   LenovoThinkpad X395 Version-
   LenovoThinkpad Yoga 11e Gen 5 Version-
   LenovoThinkpad Yoga 370 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.12% 0.28
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
psirt@lenovo.com 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.