Vulnerability Description
A local privilege escalation vulnerability in the ThinkPad Hybrid USB-C with USB-A Dock Firmware Update Tool could allow an attacker with local access to execute code with elevated privileges during the package upgrade or installation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Thinkpad Hybrid Usb-C With Usb-A Dock Firmware | < 1.0.35_v2 |
| Lenovo | Thinkpad Hybrid Usb-C With Usb-A Dock | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/product_security/LEN-103544Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-103544Vendor Advisory
FAQ
What is CVE-2022-4569?
CVE-2022-4569 is a vulnerability with a CVSS score of 7.8 (HIGH). A local privilege escalation vulnerability in the ThinkPad Hybrid USB-C with USB-A Dock Firmware Update Tool could allow an attacker with local access to execute code with elevated privileges during t...
How severe is CVE-2022-4569?
CVE-2022-4569 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-4569?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Thinkpad Hybrid Usb-C With Usb-A Dock Firmware, Lenovo Thinkpad Hybrid Usb-C With Usb-A Dock.