CVE-2024-4089
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-4089 is a new vulnerability affecting Lenovo Super File. This issue involves a DLL hijack that enables a local attacker to execute code with elevated privileges. By exploiting this vulnerability, an attacker can gain unauthorized access to sensitive data or install malware, potentially leading to significant security risks for affected systems. Lenovo has not yet released a patch for this vulnerability, leaving users vulnerable until a fix is available. It is recommended that users take precautions such as disabling Super File or limiting user permissions to mitigate potential risks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- VMG4325-B10A
Affected Vendors
- ZyXEL