CVE-2026-1717

An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to terminate arbitrary processes with elevated privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lenovo:vantage:*:*:*:*:*:*:*:*

History

25 Mar 2026, 18:22

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de validación de entrada fue reportada en el LenovoProductivitySystemAddin utilizado en Lenovo Vantage y Lenovo Baiying que podría permitir a un usuario local autenticado terminar procesos arbitrarios con privilegios elevados.
CPE cpe:2.3:a:lenovo:vantage:*:*:*:*:*:*:*:*
References () https://iknow.lenovo.com.cn/detail/438815 - () https://iknow.lenovo.com.cn/detail/438815 - Vendor Advisory
References () https://support.lenovo.com/us/en/product_security/LEN-213044 - () https://support.lenovo.com/us/en/product_security/LEN-213044 - Vendor Advisory
First Time Lenovo
Lenovo vantage

11 Mar 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-11 21:16

Updated : 2026-03-25 18:22


NVD link : CVE-2026-1717

Mitre link : CVE-2026-1717

CVE.ORG link : CVE-2026-1717


JSON object : View

Products Affected

lenovo

  • vantage
CWE
CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')