During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to perform an arbitrary file write with elevated privileges.
Advisories
No advisories yet.
Fixes
Solution
Update Lenovo Software Fix to version 7.5.5.19 or later.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-213829 |
|
History
Wed, 15 Apr 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to perform an arbitrary file write with elevated privileges. | |
| First Time appeared |
Lenovo
Lenovo software Fix |
|
| Weaknesses | CWE-59 | |
| CPEs | cpe:2.3:a:lenovo:software_fix:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lenovo
Lenovo software Fix |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2026-04-15T13:05:12.030Z
Reserved: 2026-03-13T14:48:31.899Z
Link: CVE-2026-4135
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses