Lenovo Vantage SQLite Database SQL Injection Vulnerability Allowing Elevated Code Execution

Vulnerability

A SQL injection vulnerability has been identified in Lenovo Vantage. This issue could enable a local attacker to manipulate the local SQLite database and execute code with elevated permissions.

Impact

Exploitation of this vulnerability could lead to unauthorized modification of the local SQLite database and execution of code with elevated permissions.

Added: Jul 17, 2025, 8:31 PM
Updated: Jul 17, 2025, 10:34 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
10.0
exploitability
3.3
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.