Vendor
Authentication Bypass in Lenovo Software Fix
1 TTP 1 CVECVE-2026-63427 is an authentication bypass vulnerability in Lenovo Software Fix that allows a local authenticated user to escalate privileges and execute arbitrary code.
Improper Authorization Vulnerability in Lenovo File Manager Android App
1 TTP 1 CVEA local improper authorization vulnerability in the Lenovo File Manager Android app allows authenticated local users to read or modify protected application files.
Privilege Escalation in Lenovo Filez Client
1 TTP 1 CVELenovo Filez Client contains an improper permissions vulnerability (CVE-2026-11813) that allows local authenticated users to escalate privileges.
Critical Vulnerability in Lenovo Health Android Application
1 CVEA high-severity vulnerability in the Lenovo Health Android application, exclusively distributed in the Chinese market, allows unauthorized access to sensitive user health data.
Authentication Bypass in Lenovo System Update
1 TTP 1 CVECVE-2026-6387 is an authentication bypass vulnerability in Lenovo System Update (versions prior to 5.08.04.85) that allows a local authenticated user to escalate privileges and execute arbitrary code.
Privilege Escalation Vulnerability in Lenovo Dock Manager
1 TTP 1 CVELenovo Dock Manager versions prior to 1.6.5.3 contain a local privilege escalation vulnerability due to an improperly protected key, allowing authenticated local users to gain elevated access.
Privilege Escalation Vulnerability in Lenovo Accessories and Display Manager
1 TTP 1 CVELenovo Accessories and Display Manager for Enterprise for Windows version 1.0.9 and earlier contains a hard-coded cryptographic key vulnerability (CVE-2026-63423) that allows local authenticated users to achieve arbitrary code execution with elevated privileges.
Privilege Escalation Vulnerability in Lenovo Vantage
1 TTP 1 CVELenovo Vantage and Commercial Vantage contain an improper link following vulnerability (CVE-2026-15994) that allows local authenticated users to achieve privilege escalation through file system manipulation.
OS Command Injection in Lenovo XClarity Orchestrator
1 TTP 1 CVELenovo XClarity Orchestrator (LXCO) versions prior to 2.2.0 contain an OS command injection vulnerability (CVE-2026-16793) allowing authenticated attackers to execute arbitrary commands with high privileges.
CVE-2026-9046: Insecure Permissions in Lenovo Legion Zone and App Store Leads to Local Arbitrary Code Execution
2 TTPs 1 CVECVE-2026-9046 describes an insecure permissions vulnerability in Lenovo's Legion Zone and Lenovo App Store Windows applications, distributed exclusively in the Chinese market, which, when installed on a non-system partition, allows a local low-privileged user to execute arbitrary code, leading to high impact on confidentiality, integrity, and availability.
CVE-2026-13104: Privilege Escalation in Lenovo App Store (Chinese Market)
1 TTP 1 CVEA high-severity vulnerability, CVE-2026-13104, has been identified in specific versions of the Lenovo App Store, exclusively distributed in the Chinese market, which allows a local authenticated user to execute arbitrary code with elevated privileges, potentially leading to full system compromise.
Lenovo App Store Path Traversal Vulnerability (CVE-2026-13103) Leading to Arbitrary Code Execution
1 TTP 1 CVEA critical path traversal vulnerability, identified as CVE-2026-13103, exists in the Lenovo App Store, enabling a local authenticated user to achieve arbitrary code execution on affected Windows systems within the Chinese market.
Lenovo LegionSpace 1.7.11.2 Unquoted Service Path Vulnerability
2 rules 1 TTPA local exploit has been published for Lenovo LegionSpace 1.7.11.2, detailing an Unquoted Service Path vulnerability in the 'DAService', potentially leading to local privilege escalation.
CVE-2026-5804 - Motorola Factory Test Improper Authentication Vulnerability
2 rules 1 TTP 1 CVEThe Motorola Factory Test component (com.motorola.motocit) contains an improper authentication vulnerability, allowing a local attacker to bypass permission checks and access protected device settings by leveraging a writable file descriptor in external storage to open a TCP server.
Lenovo Personal Cloud Storage Improper File Path Validation Vulnerability (CVE-2026-6282)
2 rules 1 TTP 1 CVECVE-2026-6282 describes a potential improper file path validation vulnerability in Lenovo Personal Cloud Storage devices, allowing a remote authenticated user to move or access files belonging to other users.
CVE-2026-6281: Lenovo Personal Cloud Storage Remote Command Execution
2 rules 1 TTP 1 CVECVE-2026-6281 describes a vulnerability in Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network to execute arbitrary commands on the device.
Suspicious PowerShell Engine ImageLoad
2 rules 1 TTPThis rule identifies instances where the PowerShell engine is loaded by processes other than powershell.exe, potentially indicating attackers attempting to use PowerShell functionality stealthily by using the underlying System.Management.Automation namespace and bypassing PowerShell security features.
Startup or Run Key Registry Modification
3 rules 2 TTPsAttackers modify registry run keys or startup keys to achieve persistence by referencing a program that executes when a user logs in or the system boots.