No advisories yet.
Solution
Update Vantage DeviceSettingsSystemAddin to version 1.0.8.15 or later. DeviceSettingsSystemAddin is automatically updated by Lenovo Vantage and Baiying.
Workaround
No workaround given by the vendor.
Wed, 11 Mar 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to modify arbitrary registry keys with elevated privileges. | |
| First Time appeared |
Lenovo
Lenovo baiying Lenovo vantage |
|
| Weaknesses | CWE-88 | |
| CPEs | cpe:2.3:a:lenovo:baiying:*:*:*:*:*:*:*:* cpe:2.3:a:lenovo:vantage:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Lenovo
Lenovo baiying Lenovo vantage |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2026-03-11T20:22:24.144Z
Reserved: 2026-01-30T19:00:44.486Z
Link: CVE-2026-1715
No data.
Status : Received
Published: 2026-03-11T21:16:14.807
Modified: 2026-03-11T21:16:14.807
Link: CVE-2026-1715
No data.
OpenCVE Enrichment
No data.