Skip to content
Threat Feed

Tag

Lenovo

6 briefs RSS
high advisory

Privilege Escalation Vulnerability in Lenovo Dock Manager

Lenovo Dock Manager versions prior to 1.6.5.3 contain a local privilege escalation vulnerability due to an improperly protected key, allowing authenticated local users to gain elevated access.

Dock Manager vulnerability privilege-escalation lenovo
1t 1c
high advisory

Privilege Escalation Vulnerability in Lenovo Accessories and Display Manager

Lenovo Accessories and Display Manager for Enterprise for Windows version 1.0.9 and earlier contains a hard-coded cryptographic key vulnerability (CVE-2026-63423) that allows local authenticated users to achieve arbitrary code execution with elevated privileges.

Accessories and Display Manager privilege-escalation windows lenovo cve
1t 1c
high advisory

Privilege Escalation Vulnerability in Lenovo Vantage

Lenovo Vantage and Commercial Vantage contain an improper link following vulnerability (CVE-2026-15994) that allows local authenticated users to achieve privilege escalation through file system manipulation.

Vantage +1 vulnerability privilege-escalation lenovo
1t 1c
high advisory

Lenovo App Store Path Traversal Vulnerability (CVE-2026-13103) Leading to Arbitrary Code Execution

A critical path traversal vulnerability, identified as CVE-2026-13103, exists in the Lenovo App Store, enabling a local authenticated user to achieve arbitrary code execution on affected Windows systems within the Chinese market.

Lenovo App Store vulnerability path-traversal rce lenovo
1t 1c
medium advisory

Lenovo Personal Cloud Storage Improper File Path Validation Vulnerability (CVE-2026-6282)

CVE-2026-6282 describes a potential improper file path validation vulnerability in Lenovo Personal Cloud Storage devices, allowing a remote authenticated user to move or access files belonging to other users.

Personal Cloud Storage devices cve path traversal lenovo
2r 1t 1c
high advisory

CVE-2026-6281: Lenovo Personal Cloud Storage Remote Command Execution

CVE-2026-6281 describes a vulnerability in Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network to execute arbitrary commands on the device.

Personal Cloud Storage devices cve-2026-6281 rce command injection lenovo
2r 1t 1c