VYPR

Commercial Vantage

by Lenovo

CVEs (5)

  • CVE-2025-6232HigJul 17, 2025
    risk 0.51cvss 7.8epss 0.00

    An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying specific registry locations.

  • CVE-2025-6231HigJul 17, 2025
    risk 0.51cvss 7.8epss 0.00

    An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying an application configuration file.

  • CVE-2026-15994HigAug 13, 2026
    risk 0.46cvss 7.0epss 0.00

    During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to execute code with elevated privileges.

  • CVE-2026-12036HigAug 13, 2026
    risk 0.46cvss 7.1epss 0.00

    An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to perform an arbitrary file deletion with elevated privileges.

  • CVE-2025-6230MedJul 17, 2025
    risk 0.34cvss 5.3epss 0.00

    A SQL injection vulnerability was reported in Lenovo Vantage that could allow a local attacker to modify the local SQLite database and execute limited SQLite commands.