CVE-2024-5474

MEDIUM

Lenovo Dolby Vision Provisioning - Incorrect Default Permissions

Title source: rule

Description

A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 that could allow a local attacker to read files on the system with elevated privileges during installation of the package. Previously installed versions are not affected by this issue.

Scores

CVSS v3 5.5
EPSS 0.0008
EPSS Percentile 23.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-276
Status published

Affected Products (1)

lenovo/dolby_vision_provisioning < 2.0.0.2

Timeline

Published Oct 11, 2024
Tracked Since Feb 18, 2026