CVE-2023-4706: Lenovo Preload Directory

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A privilege escalation vulnerability was reported in Lenovo preloaded devices deployed using Microsoft AutoPilot under a standard user account due to incorrect default privileges.

Affected products

  • Lenovo Preload Directory: affected versions not specified

Published 2023-11-08. Last modified 2026-06-17.