CVE-2024-4089

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Oct 11, 2024
Updated: Oct 17, 2024
CWE ID 78

Summary

CVE-2024-4089 is a new vulnerability affecting Lenovo Super File. This issue involves a DLL hijack that enables a local attacker to execute code with elevated privileges. By exploiting this vulnerability, an attacker can gain unauthorized access to sensitive data or install malware, potentially leading to significant security risks for affected systems. Lenovo has not yet released a patch for this vulnerability, leaving users vulnerable until a fix is available. It is recommended that users take precautions such as disabling Super File or limiting user permissions to mitigate potential risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share