Lenovo Vantage是中国Lenovo公司的一款联想设备管理软件。 Lenovo Vantage 10.2606.12之前版本和Lenovo Commercial Vantage 20.2026.20.0之前版本存在后置链接漏洞,该漏洞源于不正确的链接跟随,可能导致本地经过身份验证的用户以提升的权限执行代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Lenovo | Commercial Vantage | < 20.2026.20.0 |
affected |
| Lenovo | Vantage | < 10.2606.12 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Lenovo | Commercial Vantage | 0 ~ 20.2026.20.0 | - |
|
| Lenovo | Vantage | 0 ~ 10.2606.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63425 | 7.8 HIGH | Lenovo Dock Manager 权限许可和访问控制问题漏洞 |
| CVE-2026-63423 | 7.8 HIGH | Lenovo Accessories and Display Manager 加密问题漏洞 |
| CVE-2026-63424 | 7.3 HIGH | Lenovo Dock Manager 信任管理问题漏洞 |
| CVE-2026-63426 | 7.1 HIGH | Lenovo Dock Manager 后置链接漏洞 |
| CVE-2026-12036 | 7.1 HIGH | Lenovo Vantage 后置链接漏洞 |
| CVE-2026-6387 | 7.0 HIGH | Lenovo system update 授权问题漏洞 |
| CVE-2026-14256 | 4.7 MEDIUM | Lenovo ELAN TrackPoint driver 缓冲区错误漏洞 |
No comments yet