
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1715 is an input validation vulnerability in the DeviceSettingsSystemAddin component used by Lenovo Vantage and Lenovo Baiying that allows a local authenticated user to modify arbitrary Windows registry keys with elevated privileges. It affects Lenovo Vantage versions prior to 1.0.8.15 and the corresponding Lenovo Baiying application. The vulnerability was published on March 11, 2026, with a patch made available around March 25–26, 2026. It carries a CVSS v3.1 base score of 7.1 (High) (Lenovo Advisory, Red Hat CVE).
The root cause is classified as CWE-88 (Improper Neutralization of Argument Delimiters in a Command — 'Argument Injection'), meaning the DeviceSettingsSystemAddin component fails to properly validate or sanitize input before using it in privileged operations that interact with the Windows registry. An attacker with local authenticated access and low privileges can supply crafted input to the addin, causing it to write to or modify arbitrary registry keys under an elevated security context. No user interaction is required, and attack complexity is low, making exploitation straightforward for any local user on an affected system (Lenovo Advisory, Red Hat CVE).
Successful exploitation allows a low-privileged local user to modify arbitrary Windows registry keys with elevated privileges, directly impacting system integrity and availability. An attacker could alter critical system or application configuration values, disable security controls, establish persistence mechanisms, or cause application/system instability. Confidentiality is not directly impacted, but the ability to manipulate registry keys could facilitate privilege escalation or enable further attacks on the compromised host (Lenovo Advisory).
DeviceSettingsSystemAddin component exposed by Lenovo Vantage or Baiying — this may be accessible via the application's UI, IPC mechanism, or COM interface.HKLM\SOFTWARE, HKLM\SYSTEM, or autorun locations (e.g., HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run), made by the Lenovo Vantage or Baiying process.LenovoVantage.exe or related addin processes under a low-privileged user context but with elevated token.DeviceSettingsSystemAddin or associated Lenovo service processes.Lenovo has released a patched version of Lenovo Vantage (version 1.0.8.15 and later) that addresses this vulnerability; Lenovo Baiying is similarly patched. Users should update Lenovo Vantage via the Microsoft Store or Lenovo's official support channels immediately. No specific configuration-based workaround has been published; upgrading to the fixed version is the recommended remediation (Lenovo Advisory, Lenovo CN Advisory).
Community aggregators and security alert services such as RedPacket Security and Infinit Security noted the vulnerability shortly after disclosure, characterizing it as a local privilege escalation risk in Lenovo's pre-installed software ecosystem (RedPacket Security, Infinit Security). No significant vendor statements beyond the official Lenovo advisory or notable researcher commentary have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."