CVE-2022-4569

A local privilege escalation vulnerability in the ThinkPad Hybrid USB-C with USB-A Dock Firmware Update Tool could allow an attacker with local access to execute code with elevated privileges during the package upgrade or installation.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:lenovo:thinkpad_hybrid_usb-c_with_usb-a_dock_firmware:*:*:*:*:*:windows:*:*
cpe:2.3:h:lenovo:thinkpad_hybrid_usb-c_with_usb-a_dock:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:35

Type Values Removed Values Added
References () https://support.lenovo.com/us/en/product_security/LEN-103544 - Vendor Advisory () https://support.lenovo.com/us/en/product_security/LEN-103544 - Vendor Advisory

13 Jun 2023, 16:56

Type Values Removed Values Added
CPE cpe:2.3:o:lenovo:thinkpad_hybrid_usb-c_with_usb-a_dock_firmware:*:*:*:*:*:windows:*:*
cpe:2.3:h:lenovo:thinkpad_hybrid_usb-c_with_usb-a_dock:-:*:*:*:*:*:*:*
References (MISC) https://support.lenovo.com/us/en/product_security/LEN-103544 - (MISC) https://support.lenovo.com/us/en/product_security/LEN-103544 - Vendor Advisory
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

05 Jun 2023, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-05 21:15

Updated : 2024-11-21 07:35


NVD link : CVE-2022-4569

Mitre link : CVE-2022-4569

CVE.ORG link : CVE-2022-4569


JSON object : View

Products Affected

lenovo

  • thinkpad_hybrid_usb-c_with_usb-a_dock_firmware
  • thinkpad_hybrid_usb-c_with_usb-a_dock
CWE
CWE-276

Incorrect Default Permissions

NVD-CWE-noinfo