CVE-2026-15994
- EPSS 0.16%
- Veröffentlicht 13.08.2026 14:53:05
- Zuletzt bearbeitet 24.08.2026 16:45:25
During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to execute code with elevated privileges.
CVE-2026-12036
- EPSS 0.16%
- Veröffentlicht 13.08.2026 14:52:27
- Zuletzt bearbeitet 24.08.2026 16:45:25
An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to perform an arbitrary file deletion with elevated privileges.
CVE-2025-6232
- EPSS 0.19%
- Veröffentlicht 17.07.2025 19:19:32
- Zuletzt bearbeitet 22.07.2025 17:05:42
An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying specific registry locations.
CVE-2025-6231
- EPSS 0.19%
- Veröffentlicht 17.07.2025 19:19:23
- Zuletzt bearbeitet 22.07.2025 17:05:25
An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying an application configuration file.
CVE-2025-6230
- EPSS 0.15%
- Veröffentlicht 17.07.2025 19:19:12
- Zuletzt bearbeitet 19.08.2025 16:32:52
A SQL injection vulnerability was reported in Lenovo Vantage that could allow a local attacker to modify the local SQLite database and execute limited SQLite commands.