CVE-2023-4632: Lenovo System Update

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

An uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access to execute code with elevated privileges.

Affected products

  • Lenovo System Update: before 5.08.02.25 (fixed in 5.08.02.25)

Published 2023-11-08. Last modified 2026-06-17.