Vulnerabilities > Lenovo > Installation Package

DATE CVE VULNERABILITY TITLE RISK
2020-06-09 CVE-2019-6196 Untrusted Search Path vulnerability in Lenovo Installation Package
A symbolic link vulnerability in some Lenovo installation packages, prior to version 1.2.9.3, could allow privileged file operations during file extraction and installation.
local
low complexity
lenovo CWE-426
7.3
2020-06-09 CVE-2019-6173 Untrusted Search Path vulnerability in Lenovo Installation Package
A DLL search path vulnerability could allow privilege escalation in some Lenovo installation packages, prior to version 1.2.9.3, during installation if an attacker already has administrative privileges.
local
low complexity
lenovo CWE-426
6.5