7.8
CVE-2023-3112
- EPSS 0.06%
- Veröffentlicht 25.10.2023 18:17:30
- Zuletzt bearbeitet 21.11.2024 08:16:29
- Quelle psirt@lenovo.com
- CVE-Watchlists
- Unerledigt
A vulnerability was reported in Elliptic Labs Virtual Lock Sensor for ThinkPad T14 Gen 3 that could allow an attacker with local access to execute code with elevated privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ellipticlabs ≫ Ai Virtual Presence Sensor Version < 3.1.50719.1
Ellipticlabs ≫ Virtual Lock Sensor Version < 3.1.50719.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.185 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| psirt@lenovo.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-276 Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.