Vulnerability Description
A DLL search path vulnerability was reported in PaperDisplay Hotkey Service version 1.2.0.8 that could allow privilege escalation. Lenovo has ended support for PaperDisplay Hotkey software as the Night light feature introduced in Windows 10 Build 1703 provides similar features.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Yoga 700-11Isk Firmware | - |
| Lenovo | Yoga 700-11Isk | - |
| Lenovo | Yoga 700-14Isk Firmware | - |
| Lenovo | Yoga 700-14Isk | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/solutions/LEN-27569Vendor Advisory
- https://support.lenovo.com/solutions/LEN-27569Vendor Advisory
FAQ
What is CVE-2019-6165?
CVE-2019-6165 is a vulnerability with a CVSS score of 7.8 (HIGH). A DLL search path vulnerability was reported in PaperDisplay Hotkey Service version 1.2.0.8 that could allow privilege escalation. Lenovo has ended support for PaperDisplay Hotkey software as the Nigh...
How severe is CVE-2019-6165?
CVE-2019-6165 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-6165?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Yoga 700-11Isk Firmware, Lenovo Yoga 700-11Isk, Lenovo Yoga 700-14Isk Firmware, Lenovo Yoga 700-14Isk.