CVE-2024-5474

A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 that could allow a local attacker to read files on the system with elevated privileges during installation of the package. Previously installed versions are not affected by this issue.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:lenovo:dolby_vision_provisioning:*:*:*:*:*:*:*:*

History

15 Nov 2024, 17:00

Type Values Removed Values Added
References () https://support.lenovo.com/us/en/product_security/LEN-158394 - () https://support.lenovo.com/us/en/product_security/LEN-158394 - Vendor Advisory
First Time Lenovo dolby Vision Provisioning
Lenovo
CPE cpe:2.3:a:lenovo:dolby_vision_provisioning:*:*:*:*:*:*:*:*

15 Oct 2024, 12:58

Type Values Removed Values Added
Summary
  • (es) Se informó de una posible vulnerabilidad de divulgación de información en el paquete de software Dolby Vision Provisioning de Lenovo anterior a la versión 2.0.0.2 que podría permitir que un atacante local lea archivos en el sistema con privilegios elevados durante la instalación del paquete. Las versiones instaladas anteriormente no se ven afectadas por este problema.

11 Oct 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-11 16:15

Updated : 2024-11-15 17:00


NVD link : CVE-2024-5474

Mitre link : CVE-2024-5474

CVE.ORG link : CVE-2024-5474


JSON object : View

Products Affected

lenovo

  • dolby_vision_provisioning
CWE
CWE-276

Incorrect Default Permissions