CVE-2024-5474
MEDIUMLenovo Dolby Vision Provisioning - Incorrect Default Permissions
Title source: ruleDescription
A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 that could allow a local attacker to read files on the system with elevated privileges during installation of the package. Previously installed versions are not affected by this issue.
Scores
CVSS v3
5.5
EPSS
0.0008
EPSS Percentile
23.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-276
Status
published
Affected Products (1)
lenovo/dolby_vision_provisioning
< 2.0.0.2
Timeline
Published
Oct 11, 2024
Tracked Since
Feb 18, 2026