CVE-2024-33579
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2024-33579 is a newly disclosed vulnerability affecting Lenovo Baiying software. This issue involves a DLL hijack vulnerability where a local attacker can manipulate the application to load a malicious DLL instead of the intended one, thereby gaining elevated privileges. This vulnerability poses a significant risk, particularly in enterprise environments where Lenovo Baiying is widely used. Attackers could exploit this to install malware, steal sensitive information, or carry out other malicious activities, underscoring the importance of prompt patching and secure configuration management practices.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Lenovo