CVE-2024-23594: Lenovo Preload Directory

Medium severity, CVSS 6.4. EPSS: 0.2% chance of exploitation in the next 30 days.

A buffer overflow vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from 2012 to 2014 that could allow a privileged attacker with local access to execute arbitrary code.

Affected products

  • Lenovo Preload Directory: from 7, up to and including 8
  • Lenovo Windows 7 And 8 Pc Preloads

Published 2024-04-15. Last modified 2026-06-17.