CVE-2024-12673: Lenovo Vantage

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

An improper privilege vulnerability was reported in a BIOS customization feature of Lenovo Vantage on SMB notebook devices which could allow a local attacker to elevate privileges on the system. This vulnerability only affects Vantage installed on these devices: * Lenovo V Series (Gen 5) * ThinkBook 14 (Gen 6, 7) * ThinkBook 16 (Gen 6, 7) * ThinkPad E Series (Gen 1)

Affected products

  • Lenovo Vantage: before 10.2501.15.0 (fixed in 10.2501.15.0)

Published 2025-02-12. Last modified 2026-06-17.