CVE-2026-1716
published 2026-03-11CVE-2026-1716: An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local…
PriorityP432high7.1CVSS 3.1
AVLACLPRLUINSUCNIHAH
EPSS
0.15%
4.4th percentile
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to delete arbitrary registry keys with elevated privileges.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lenovo | baiying | < 1.0.8.15 | 1.0.8.15 |
| lenovo | vantage | < 1.0.8.15 | 1.0.8.15 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv4.06.9MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-13154 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2025-13154 [MEDIUM] CVE-2025-13154 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-13154 :
Lenovo Vantage vulnerability analysis and mitigation
An improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.
Source : NVD
## 6.8
Score
Published January 14, 2026
Severity MEDIUM
CNA Score 6.8
Affected Technologies
Lenovo Vantage
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:lenovo:vantage
Sources
NVD
Windows Severity MEDIUM Has Fix Added at: Jan 18, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cl
Wiz
CVE-2026-1717 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2026-1717 [MEDIUM] CVE-2026-1717 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1717 :
Lenovo Vantage vulnerability analysis and mitigation
An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to terminate arbitrary processes with elevated privileges.
Source : NVD
## 6.8
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 6.8
Affected Technologies
Lenovo Vantage
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:lenovo:vantage
Sources
Windows Severity MEDIUM Has Fix Added at: Mar 19, 2026
Windows Severity MEDIUM Has Fix Added at: Mar 29, 2026
## G
Wiz
CVE-2026-1716 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2026-1716 [MEDIUM] CVE-2026-1716 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1716 :
Lenovo Vantage vulnerability analysis and mitigation
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to delete arbitrary registry keys with elevated privileges.
Source : NVD
## 6.9
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 6.9
Affected Technologies
Lenovo Vantage
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:lenovo:vantage
Sources
Windows Severity HIGH Has Fix Added at: Mar 19, 2026
Windows Severity HIGH Has Fix Added at: Mar 29, 2026
## Get a CV
Wiz
CVE-2026-1715 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2026-1715 [MEDIUM] CVE-2026-1715 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1715 :
Lenovo Vantage vulnerability analysis and mitigation
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to modify arbitrary registry keys with elevated privileges.
Source : NVD
## 6.9
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 6.9
Affected Technologies
Lenovo Vantage
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:lenovo:vantage
Sources
Windows Severity HIGH Has Fix Added at: Mar 19, 2026
Windows Severity HIGH Has Fix Added at: Mar 29, 2026
## Get a CV
2026-03-11
Published