CVE-2024-12673

An improper privilege vulnerability was reported in a BIOS customization feature of Lenovo Vantage on SMB notebook devices which could allow a local attacker to elevate privileges on the system. This vulnerability only affects Vantage installed on these devices: * Lenovo V Series (Gen 5) * ThinkBook 14 (Gen 6, 7) * ThinkBook 16 (Gen 6, 7) * ThinkPad E Series (Gen 1)
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Se informó de una vulnerabilidad de privilegios indebidos en una función de personalización del BIOS de Lenovo Vantage en dispositivos portátiles SMB que podría permitir que un atacante local elevara los privilegios en el sistema. Esta vulnerabilidad solo afecta a Vantage instalado en estos dispositivos: * Lenovo V Series (Gen 5) * ThinkBook 14 (Gen 6, 7) * ThinkBook 16 (Gen 6, 7) * ThinkPad E Series (Gen 1)

12 Feb 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-12 21:15

Updated : 2026-04-15 00:35


NVD link : CVE-2024-12673

Mitre link : CVE-2024-12673

CVE.ORG link : CVE-2024-12673


JSON object : View

Products Affected

No product.

CWE
CWE-250

Execution with Unnecessary Privileges