CVE-2026-63427
largeAuthentication Bypass in Lenovo Software Fix Enables Local Privilege Escalation
Lenovo has disclosed an authentication bypass (CWE-290) in its Software Fix utility that allows a local, low-privileged authenticated user to gain elevated privileges and execute arbitrary code on the affected machine. The flaw is triggered locally: an attacker or user who can already run code in a low-privileged account on a system with Software Fix installed bypasses the tool's authentication logic to act with higher privileges, without requiring user interaction. Successful exploitation results in full local privilege escalation, with high impact on the confidentiality, integrity, and availability of the local system (CVSS 4.0 base 8.5: AV:L/AC:L/PR:L/UI:N). Affected users are those with Lenovo Software Fix installed on their systems; the CVE record does not specify affected version ranges, so organizations should consult Lenovo's PSIRT advisory for exact version details. There is currently no evidence of exploitation in the wild, no known public proof-of-concept, and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog.
What to do: Check whether Lenovo Software Fix is installed on managed endpoints and update it to the fixed version specified in Lenovo's PSIRT advisory at support.lenovo.com. Because the attack vector is local, prioritize remediation on shared, kiosk, and multi-user machines where untrusted or low-privileged local accounts exist, and restrict local logon rights on systems awaiting the update.
| Lenovo Software Fix | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.
- Weakness
- CWE-290
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.