vendor:
Lenovo Hotkey Driver and Access Connections
by:
Chilik Tamir - Amdocs Power Security Testing Group
N/A
CVSS
HIGH
Privilege escalation
CWE
Product Name: Lenovo Hotkey Driver and Access Connections
Affected Version From:
Affected Version To: v5.33
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
2010
Security vulnerability in Lenovo Hotkey Driver and Access Connections version <=v5.33
A privilege escalation attack can be used as a backdoor to bypass login and run arbitrary code as a System user on Lenovo or Thinkpad laptops running Access Connection v5.33 and earlier versions (tracked back to version 4)
Mitigation:
Unknown