HIGH · 7.8

CVE-2019-6165

A DLL search path vulnerability was reported in PaperDisplay Hotkey Service version 1.2.0.8 that could allow privilege escalation. Lenovo has ended support for PaperDisplay Hotkey software as the Nigh...

Vulnerability Description

A DLL search path vulnerability was reported in PaperDisplay Hotkey Service version 1.2.0.8 that could allow privilege escalation. Lenovo has ended support for PaperDisplay Hotkey software as the Night light feature introduced in Windows 10 Build 1703 provides similar features.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LenovoYoga 700-11Isk Firmware-
LenovoYoga 700-11Isk-
LenovoYoga 700-14Isk Firmware-
LenovoYoga 700-14Isk-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-6165?

CVE-2019-6165 is a vulnerability with a CVSS score of 7.8 (HIGH). A DLL search path vulnerability was reported in PaperDisplay Hotkey Service version 1.2.0.8 that could allow privilege escalation. Lenovo has ended support for PaperDisplay Hotkey software as the Nigh...

How severe is CVE-2019-6165?

CVE-2019-6165 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-6165?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Yoga 700-11Isk Firmware, Lenovo Yoga 700-11Isk, Lenovo Yoga 700-14Isk Firmware, Lenovo Yoga 700-14Isk.