Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Lenovo Software Fix to version 7.5.5.19 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-213829 |
|
Wed, 15 Apr 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Privilege Escalation During Lenovo Software Fix Installation |
Wed, 15 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Apr 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to execute code with elevated privileges. | |
| First Time appeared |
Lenovo
Lenovo software Fix |
|
| Weaknesses | CWE-427 | |
| CPEs | cpe:2.3:a:lenovo:software_fix:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lenovo
Lenovo software Fix |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2026-04-15T13:08:19.333Z
Reserved: 2026-03-13T14:48:30.665Z
Link: CVE-2026-4134
Updated: 2026-04-15T13:07:45.969Z
Status : Awaiting Analysis
Published: 2026-04-15T13:16:24.480
Modified: 2026-04-17T15:09:46.880
Link: CVE-2026-4134
No data.
OpenCVE Enrichment
Updated: 2026-04-15T14:52:54Z