Back

HIGH

A DLL search path vulnerability was reported in the Lenovo HardwareScan Plugin for the Lenovo Vantage hardware scan feature prior to version 1.0.46.11 that could allow escalation of privilege

Published Oct 14, 2020

Description

A DLL search path vulnerability was reported in the Lenovo HardwareScan Plugin for the Lenovo Vantage hardware scan feature prior to version 1.0.46.11 that could allow escalation of privilege.

Affected products

Remediation

Vendor solution

Update the Lenovo HardwareScan Plugin to version 1.0.46.11.

The Lenovo HardwareScan Plugin is automatically updated by the Lenovo System Interface Foundation Service. To immediately start the update process, reboot the computer or restart the "System Interface Foundation Service" service.

To verify the Lenovo HardwareScan Plugin version: Open File Explorer and navigate to C:\ProgramData\Lenovo\ImController\Plugins\LenovoHardwareScanPlugin\x64 Right click on LenovoHardwareScanPlugin.dll and select Properties. Click on the Details tab. Read the File version.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner lenovo
Published Oct 14, 2020
Updated Aug 4, 2024
Reserved Jan 28, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner lenovo
Published Oct 14, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2020-29212