CVE-2024-4696

A privilege escalation vulnerability was reported in Lenovo Service Bridge prior to version 5.0.2.17 that could allow operating system commands to be executed if a specially crafted link is visited.
Configurations

No configuration.

History

21 Nov 2024, 09:43

Type Values Removed Values Added
References () https://support.lenovo.com/us/en/product_security/LEN-163429 - () https://support.lenovo.com/us/en/product_security/LEN-163429 -

17 Jun 2024, 12:43

Type Values Removed Values Added
Summary
  • (es) Se informó una vulnerabilidad de escalada de privilegios en Lenovo Service Bridge antes de la versión 5.0.2.17 que podría permitir la ejecución de comandos del sistema operativo si se visita un enlace especialmente manipulado.

13 Jun 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-13 20:15

Updated : 2024-11-21 09:43


NVD link : CVE-2024-4696

Mitre link : CVE-2024-4696

CVE.ORG link : CVE-2024-4696


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')