CVE-2023-29057 Information

Description

A valid XCC user’s local account permissions overrides their active directory permissions under specific configurations. This could lead to a privilege escalation. To be vulnerable LDAP must be configured for authentication/authorization and logins configured as “Local First then LDAP”.

Reference

https://support.lenovo.com/us/en/product_security/LEN-118321

Share on: