CVE-2024-12673 is an improper privilege vulnerability in a BIOS customization feature of Lenovo Vantage, affecting specific Lenovo V Series, ThinkBook, and ThinkPad E Series notebook devices. A local attacker could exploit this with low complexity to achieve high impact, including privilege escalation, compromising confidentiality, integrity, and availability. The vulnerability has a CVSS score of 7.8 (High) but is not currently listed in CISA's KEV catalog, nor is there any public exploit code or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 10.2501.15.0CPE match | cpe:2.3:a:lenovo:vantage:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.