CVE-2026-1716

An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to delete arbitrary registry keys with elevated privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lenovo:vantage:*:*:*:*:*:*:*:*

History

25 Mar 2026, 18:23

Type Values Removed Values Added
CPE cpe:2.3:a:lenovo:vantage:*:*:*:*:*:*:*:*
Summary
  • (es) Una vulnerabilidad de validación de entrada fue reportada en el DeviceSettingsSystemAddin utilizado en Lenovo Vantage y Lenovo Baiying que podría permitir a un usuario local autenticado eliminar claves de registro arbitrarias con privilegios elevados.
First Time Lenovo
Lenovo vantage
References () https://iknow.lenovo.com.cn/detail/438815 - () https://iknow.lenovo.com.cn/detail/438815 - Vendor Advisory
References () https://support.lenovo.com/us/en/product_security/LEN-213044 - () https://support.lenovo.com/us/en/product_security/LEN-213044 - Vendor Advisory

11 Mar 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-11 21:16

Updated : 2026-03-25 18:23


NVD link : CVE-2026-1716

Mitre link : CVE-2026-1716

CVE.ORG link : CVE-2026-1716


JSON object : View

Products Affected

lenovo

  • vantage
CWE
CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')