A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticated user to execute code with elevated privileges.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to the Lenovo Service Bridge version 5.0.2.20 or later. Lenovo Service Bridge is updated automatically.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-211071 |
|
History
Wed, 15 Apr 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Potential DLL Hijacking in Lenovo Service Bridge Enables Local Privilege Escalation |
Wed, 15 Apr 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticated user to execute code with elevated privileges. | |
| First Time appeared |
Lenovo
Lenovo service Bridge |
|
| Weaknesses | CWE-427 | |
| CPEs | cpe:2.3:a:lenovo:service_bridge:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lenovo
Lenovo service Bridge |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2026-04-15T13:34:44.767Z
Reserved: 2026-01-29T16:42:53.823Z
Link: CVE-2026-1636
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-04-15T13:38:28Z
Weaknesses