CVE-2024-33579

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Oct 11, 2024
Updated: Oct 15, 2024
CWE ID 427

Summary

CVE-2024-33579 is a newly disclosed vulnerability affecting Lenovo Baiying software. This issue involves a DLL hijack vulnerability where a local attacker can manipulate the application to load a malicious DLL instead of the intended one, thereby gaining elevated privileges. This vulnerability poses a significant risk, particularly in enterprise environments where Lenovo Baiying is widely used. Attackers could exploit this to install malware, steal sensitive information, or carry out other malicious activities, underscoring the importance of prompt patching and secure configuration management practices.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share