Multiple vulnerabilities in Lenovo PCManager



Risk Low
Patch available YES
Number of vulnerabilities 2
CVE-ID CVE-2021-3451
CVE-2021-3464
CWE-ID CWE-276
CWE-427
Exploitation vector Local
Public exploit N/A
Vulnerable software
PCManager
Other software / Other software solutions

Vendor Lenovo

Security Bulletin

This security bulletin contains information about 2 vulnerabilities.

1) Incorrect default permissions

EUVDB-ID: #VU52693

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-3451

CWE-ID: CWE-276 - Incorrect Default Permissions

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to incorrect default permissions for files and folders that are set by the application. A local user send a specially crafted request and cause a denial of service condition.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

PCManager: before 3.0.400.3252

CPE2.3 External links

https://iknow.lenovo.com.cn/detail/dc_196156.html


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Insecure DLL loading

EUVDB-ID: #VU52694

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-3464

CWE-ID: CWE-427 - Uncontrolled Search Path Element

Exploit availability: No

Description

The vulnerability allows a local user to compromise vulnerable system.

The vulnerability exists due to a DLL search path flaw. A local user can use a specially crafted .DLL file and gain elevated privileges.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

PCManager: before 3.0.400.3252

CPE2.3 External links

https://iknow.lenovo.com.cn/detail/dc_196156.html


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###