ID

VAR-201908-1862


CVE

CVE-2019-10724


TITLE

plural Lenovo Vulnerabilities related to authorization, authority, and access control in products

Trust: 0.8

sources: JVNDB: JVNDB-2019-008838

DESCRIPTION

There is a vulnerability with the Dolby DAX2 API system services in which a low-privileged user can terminate arbitrary processes that are running at a higher privilege. The following are affected products and versions: Legion Y520T_Z370 6.0.1.8642, AIO310-20IAP 6.0.1.8642, AIO510-22ISH 6.0.1.8642, AIO510-23ISH 6.0.1.8642, AIO520-22IKL 6.0.1.8642, AIO520-22IKU 6.0.1.8642, AIO520-24IKL 6.0.1.8642, AIO520-24IKU 6.0.1.8642, AIO520-27IKL 6.0.1.8642, AIO720-24IKB 6.0.1.8642, IdeaCentre 520S-23IKU 6.0.1.8642, ThinkCentre M700z 6.0.1.8642, ThinkCentre M800z 6.0.1.8642, ThinkCentre M810z 6.0.1.8642, ThinkCentre M818z 6.0.1.8642, ThinkCentre M900Z 6.0.1.8642, ThinkCentre M910z 6.0.1.8642, V410z(YT S4250) 6.0.1.8642, 330-14IKBR Win10:6.0.1.8652, 330-15IKBR Win10:6.0.1.8652, 330-15IKBR (Brazil) Win10:6.0.1.8652, 330-15IKBR Touch Win10:6.0.1.8652, 330-17IKBR Win10:6.0.1.8652, YOGA 730-13IKB Win10:6.0.1.8644, YOGA 730-15IKB Win10:6.0.1.8644, ThinkPad L560 6.0.1.8644 and 6.0.1.8652, ThinkPad L570 6.0.1.8644 and 6.0.1.8652, ThinkPad P50 6.0.1.8642, ThinkPad P50s 6.0.1.8642, ThinkPad P51s (20Jx, 20Kx) 6.0.1.8642, ThinkPad P51s (20Hx) 6.0.1.8642, ThinkPad P52s 6.0.1.8642, ThinkPad P70 6.0.1.8642, ThinkPad T25 6.0.1.8642, ThinkPad T460s 6.0.1.8642, ThinkPad T470 6.0.1.8642, ThinkPad T470s 6.0.1.8642, ThinkPad T480 6.0.1.8642, ThinkPad T480s 6.0.1.8642, ThinkPad T560 6.0.1.8642, ThinkPad T570 6.0.1.8642, ThinkPad T580 6.0.1.8642, ThinkPad X1 Carbon 8.66.76.72 and 8.66.68.54, ThinkPad X1 Carbon 6th 6.0.1.8642, ThinkPad X1 Carbon, X1 Yoga 8.66.62.92 and 8.66.62.54, ThinkPad X1 Tablet (20Gx) 6.0.1.8642, ThinkPad X1 Tablet (20Jx) 6.0.1.8642, ThinkPad X1 Tablet Gen 3 6.0.1.8642, ThinkPad X1 Yoga (20Jx) 8.66.88.60, ThinkPad X1 Yoga 3rd 6.0.1.8642, ThinkPad X280 6.0.1.8642, ThinkPad Yoga 260, S1 8.66.62.92 and 8.66.62.54. plural Lenovo The product contains vulnerabilities related to authorization, permissions, and access control.Service operation interruption (DoS) There is a possibility of being put into a state. Dolby DAX2 API Service is an audio service component of Dolby Laboratories. An attacker could exploit this vulnerability to cause a denial of service

Trust: 1.71

sources: NVD: CVE-2019-10724 // JVNDB: JVNDB-2019-008838 // VULHUB: VHN-142299

AFFECTED PRODUCTS

vendor:lenovomodel:thinkpad l560scope:ltversion:6.0.1.8644

Trust: 1.0

vendor:lenovomodel:thinkpad p50scope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:thinkpad x1 tabletscope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:330-15ikbr touchscope:ltversion:6.0.1.8652

Trust: 1.0

vendor:lenovomodel:thinkpad t570scope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:thinkpad x280scope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:thinkpad e460scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad t25scope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:thinkpad t470sscope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:thinkpad 11e yogascope:eqversion: -

Trust: 1.0

vendor:lenovomodel:flex 5-1570\scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:miix 520-12ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad t480sscope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:aio310-20iapscope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:aio520-22ikuscope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:thinkpad x1 yoga 3rdscope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:thinkpad l380scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:aio510-23ishscope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:thinkpad l570scope:ltversion:6.0.1.8644

Trust: 1.0

vendor:lenovomodel:thinkcentre m900zscope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:thinkpad yoga 260scope:ltversion:8.66.62.92

Trust: 1.0

vendor:lenovomodel:thinkpad x270scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga c930-13ikb glassscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad x1 yogascope:ltversion:8.66.62.92

Trust: 1.0

vendor:lenovomodel:thinkpad p51sscope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:330-15ikbrscope:ltversion:6.0.1.8652

Trust: 1.0

vendor:lenovomodel:yoga book c930scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad e475scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:aio520-24ikuscope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:thinkpad l580scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:k43c-80scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad t470scope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:aio520-22iklscope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:thinkcentre m818zscope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:thinkpad e580scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad l470scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m700zscope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:720s-15ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad t580scope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:v330-14iskscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad e585scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:aio510-22ishscope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:flex 5-1470\scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad e560scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad s3 yoga 14scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v330-15iskscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:aio720-24ikbscope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:thinkpad t460sscope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:thinkpad x1 carbonscope:ltversion:8.66.76.72

Trust: 1.0

vendor:lenovomodel:330-14ikbrscope:ltversion:6.0.1.8652

Trust: 1.0

vendor:lenovomodel:b330-15ikbrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad e465scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad yoga 370scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga 730-13ikbscope:ltversion:6.0.1.8644

Trust: 1.0

vendor:lenovomodel:thinkpad a275scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad l380 yogascope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad e560pscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:720s touch-15ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:aio520-27iklscope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:yoga c930-13ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga 14scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v330-14ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m810zscope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:thinkpad p50sscope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:thinkpad yoga s1scope:ltversion:8.66.62.92

Trust: 1.0

vendor:lenovomodel:miix 525-12ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad p52sscope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:thinkpad l460scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:e43-80scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad a475scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad e480scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad t480scope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:thinkpad t560scope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:thinkpad e485scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad e570scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad 13scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad 11escope:eqversion: -

Trust: 1.0

vendor:lenovomodel:100e 2nd genscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:k42-80scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:e53-80scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:300e 2nd genscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:yoga 520-14ikbrscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v720-14scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad p40scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad e470scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad t460scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad t460pscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad x380 yogascope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad s1 3rdscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:ideacentre 520s-23ikuscope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:v730-15ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:v330-15ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad e575scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad p70scope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:aio520-24iklscope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:v410z\scope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:thinkpad e565scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad t470pscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:330-17ikbrscope:ltversion:6.0.1.8652

Trust: 1.0

vendor:lenovomodel:legion y520t z370scope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:yoga 720-12ikbscope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad s3-s440scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m800zscope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:yoga 730-15ikbscope:ltversion:6.0.1.8644

Trust: 1.0

vendor:lenovomodel:thinkpad s5scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkcentre m910zscope:ltversion:6.0.1.8642

Trust: 1.0

vendor:lenovomodel:thinkpad x260scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:thinkpad l480scope:eqversion: -

Trust: 1.0

vendor:lenovomodel:aio310-20iapscope: - version: -

Trust: 0.8

vendor:lenovomodel:aio510-22ishscope: - version: -

Trust: 0.8

vendor:lenovomodel:aio510-23ishscope: - version: -

Trust: 0.8

vendor:lenovomodel:aio520-22iklscope: - version: -

Trust: 0.8

vendor:lenovomodel:aio520-22ikuscope: - version: -

Trust: 0.8

vendor:lenovomodel:aio520-24iklscope: - version: -

Trust: 0.8

vendor:lenovomodel:aio520-24ikuscope: - version: -

Trust: 0.8

vendor:lenovomodel:aio520-27iklscope: - version: -

Trust: 0.8

vendor:lenovomodel:aio720-24ikbscope: - version: -

Trust: 0.8

vendor:lenovomodel:legion y520t z370scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2019-008838 // NVD: CVE-2019-10724

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-10724
value: MEDIUM

Trust: 1.0

NVD: CVE-2019-10724
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201904-968
value: MEDIUM

Trust: 0.6

VULHUB: VHN-142299
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2019-10724
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-142299
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-10724
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-142299 // JVNDB: JVNDB-2019-008838 // CNNVD: CNNVD-201904-968 // NVD: CVE-2019-10724

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-264

Trust: 0.9

sources: VULHUB: VHN-142299 // JVNDB: JVNDB-2019-008838 // NVD: CVE-2019-10724

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201904-968

TYPE

permissions and access control issues

Trust: 0.6

sources: CNNVD: CNNVD-201904-968

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-008838

PATCH

title:レノボ セキュリティ アドバイザリurl:https://lenovomobilesupport.lenovo.com/jp/ja/product_security/home

Trust: 0.8

title:LEN-26251url:https://support.lenovo.com/jp/ja/solutions/len-26251

Trust: 0.8

title:Dolby DAX2 API Service Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=91781

Trust: 0.6

sources: JVNDB: JVNDB-2019-008838 // CNNVD: CNNVD-201904-968

EXTERNAL IDS

db:NVDid:CVE-2019-10724

Trust: 2.5

db:LENOVOid:LEN-26251

Trust: 1.7

db:JVNDBid:JVNDB-2019-008838

Trust: 0.8

db:CNNVDid:CNNVD-201904-968

Trust: 0.7

db:VULHUBid:VHN-142299

Trust: 0.1

sources: VULHUB: VHN-142299 // JVNDB: JVNDB-2019-008838 // CNNVD: CNNVD-201904-968 // NVD: CVE-2019-10724

REFERENCES

url:https://lenovomobilesupport.lenovo.com/us/en/product_security/home

Trust: 1.7

url:https://support.lenovo.com/us/en/solutions/len-26251

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2019-10724

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-10724

Trust: 0.8

url:https://support.lenovo.com/us/zh/solutions/len-26251

Trust: 0.6

url:https://support.lenovo.com/us/en/product_security/len-26251

Trust: 0.6

sources: VULHUB: VHN-142299 // JVNDB: JVNDB-2019-008838 // CNNVD: CNNVD-201904-968 // NVD: CVE-2019-10724

SOURCES

db:VULHUBid:VHN-142299
db:JVNDBid:JVNDB-2019-008838
db:CNNVDid:CNNVD-201904-968
db:NVDid:CVE-2019-10724

LAST UPDATE DATE

2024-11-23T23:11:44.569000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-142299date:2020-08-24T00:00:00
db:JVNDBid:JVNDB-2019-008838date:2019-09-06T00:00:00
db:CNNVDid:CNNVD-201904-968date:2020-08-25T00:00:00
db:NVDid:CVE-2019-10724date:2024-11-21T04:19:48.827

SOURCES RELEASE DATE

db:VULHUBid:VHN-142299date:2019-08-29T00:00:00
db:JVNDBid:JVNDB-2019-008838date:2019-09-06T00:00:00
db:CNNVDid:CNNVD-201904-968date:2019-04-20T00:00:00
db:NVDid:CVE-2019-10724date:2019-08-29T00:15:10.577