CVE-2026-9045 Details
Description
During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.
A vulnerability allowing local authenticated users to execute arbitrary code with elevated privileges has been identified in Lenovo Accessories and Display Manager for Enterprise for Windows. This issue was discovered during an internal security assessment.
Users are advised to update Lenovo Accessories and Display Manager for Enterprise for Windows to version 1.0.9 or later. The updated version can be downloaded from the Lenovo Drivers & Software support site.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.lenovo.com/us/en/downloads/ds568567 | [email protected] | |
| https://support.lenovo.com/us/en/product_security/LEN-213623 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 10, 2026 | New CVE Received | [email protected] |