Executive brief
Lenovo Smart Connect for Windows, a tool used to integrate Lenovo PCs with mobile devices, contains a security flaw that could allow a user already logged into the computer to bypass authentication. If exploited, this would allow a person with limited access to run unauthorized commands with high-level system privileges. This could lead to a full compromise of the device, including the ability to access sensitive data or install malicious software.
Technical details
An authentication bypass vulnerability (CWE-290) exists in Lenovo Smart Connect for Windows. The flaw allows a local authenticated user with low privileges to bypass security checks, potentially through spoofing, to execute arbitrary code with elevated (SYSTEM-level) privileges. The attack requires local access to the machine but does not require user interaction. Lenovo has acknowledged the issue and users are advised to refer to the official Lenovo security advisory LEN-218281 for remediation steps and patched versions.
Affected products
- Lenovo Smart Connect for Windows
Timeline
- 2026-06-10: disclosed
- 2026-06-10: advisory