在联想 Software Fix 中发现了一个认证绕过漏洞,允许本地已认证用户以提升的权限执行任意代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Lenovo | Software Fix | < 7.6.2.10 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Lenovo | Software Fix | 0 ~ 7.6.2.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75940 | 9.1 CRITICAL | 联想健康App敏感健康信息泄露漏洞 |
| CVE-2026-11813 | 7.8 HIGH | Lenovo Filez Client权限不当致本地权限提升 |
| CVE-2026-19136 | 7.8 HIGH | 天息AI智能体PC应用命令注入漏洞 |
| CVE-2026-18994 | 7.1 HIGH | 联想文件管理器授权不当致本地文件读写 |
No comments yet