Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to the Lenovo Service Bridge version 5.0.2.17 or later. If you previously installed Lenovo Service Bridge, the update will be performed automatically.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-44294 | A privilege escalation vulnerability was reported in Lenovo Service Bridge prior to version 5.0.2.17 that could allow operating system commands to be executed if a specially crafted link is visited. |
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-163429 |
|
No history.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-08-01T20:47:41.519Z
Reserved: 2024-05-09T16:18:19.615Z
Link: CVE-2024-4696
Updated: 2024-08-01T20:47:41.519Z
Status : Deferred
Published: 2024-06-13T20:15:15.697
Modified: 2026-06-17T08:02:25.977
Link: CVE-2024-4696
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:45:01Z
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
EUVD