CVE-2024-4763
📛 CVE Title
CVE-2024-4763
Description
An insecure driver vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) that could allow a local attacker to escalate privileges to kernel.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- lenovo
- CVSS severity
- HIGH
- CVSS score
- 7.8 / 10
- CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H- Effective score
- 7.8 / 10 HIGH source: CNA overview
- CWE(s)
-
CWE-276 - Reserved
- 2024-05-10
- Published
- 2024-08-16 16:17 UTC
- Last updated
- 2024-08-16 17:08 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/4xxx/CVE-2024-4763.json
- Linked Threat
- CVE-2024-4763 — CVE-2024-4763
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2024-44359 - Assigner
- lenovo
- Published
- Aug 16, 2024, 2:17:13 PM
- Updated
- Aug 16, 2024, 3:08:37 PM
- EUVD base score (CVSS 3.1)
-
7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EUVD-reported EPSS
- 0.0500
- Vendors
- Lenovo
- Products
-
Accessories and Display Manager (0 <1.0.3.05)Display Control Center (0 <3.0.29082.0)
- Aliases
-
GHSA-5cv5-pc9w-5hgp
ENISA description: An insecure driver vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) that could allow a local attacker to escalate privileges to kernel.
EUVD references (1)
Affected products (2)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Lenovo | Display Control Center |
0 (affected)
|
— |
| Lenovo | Accessories and Display Manager |
0 (affected)
|
— |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
Remediations (18)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:cybernews.com
Microsoft's July 2026 Patch Tuesday fixes a record 622 vulnerabilities and begins mandatory Kerberos RC4 enforcement, marking one of Windows' biggest security updates.
2026-08-05 12:57 UTC -
web:msrc.microsoft.com
The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.
2026-08-05 12:57 UTC -
web:msrc.microsoft.com
Security Update Guide - Microsoft Security Response Center
2026-08-05 12:57 UTC -
web:support.microsoft.com
Improvements and fixes This security update introduces the SharePoint Server Subscription Edition Version 26H1 feature update. This feature update will be included in all SharePoint Server Subscription Edition public updates going forward. For more information about this feature update, see New and improved features in SharePoint Server Subscription Edition Version 26H1. This link may be ...
2026-08-05 12:57 UTC -
web:www.cisa.gov
The median time for full resolution rose to 43 days. Defenders need greater clarity and speed to patch systems in today's threat landscape. We must flip the script on patching prioritization: patch smarter, not harder.
2026-08-05 12:57 UTC -
web:www.microsoft.com
Microsoft's free Security Update Guide Notifications provide links to security-related software updates and notification of re-released security updates. These notifications are sent via email throughout the month as needed. You can choose the type of updates for which you want to be notified: Major ...
2026-08-05 12:57 UTC -
web:www.oracle.com
Prior Critical Patch Update and Critical Security Patch Update advisories should be reviewed for information regarding earlier published security patches. Refer to Critical Patch Updates, Critical Security Patch Updates, Security Alerts and Bulletins for information about Oracle Security advisories.
2026-08-05 12:57 UTC -
web:www.tenable.com
Microsoft patched 569 CVEs in July 2026, the largest Patch Tuesday release in its history. 56 critical CVEs patched including three zero-day vulnerabilities.
2026-08-05 12:57 UTC -
web:www.computerworld.com
Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...
2026-05-22 10:38 UTC -
web:www.crowdstrike.com
Microsoft's March 2026 Patch Tuesday addresses 82 CVEs , featuring eight Critical vulnerabilities.
2026-05-22 10:38 UTC -
web:www.forbes.com
Microsoft starts expiring critical Secure Boot certificates in just 2 weeks.
2026-05-22 10:38 UTC -
web:cybersecuritynews.com
Microsoft released an out-of-band hotpatch update on March 13, 2026, addressing serious security vulnerabilities in Windows 11 versions 24H2 and 25H2.
2026-05-22 10:38 UTC -
web:www.ibm.com
Updates listed within IBM Fix Central without a key symbol are generally available for installation subject to the terms of the applicable license agreement. Any copying, reproduction, distribution, or installation of code, other than as expressly authorized by IBM, is prohibited.
2026-05-22 10:38 UTC -
web:www.maketecheasier.com
Check out the latest Windows 11 and Windows 10 update problems and their solutions, as recommended by Microsoft experts.
2026-05-22 10:38 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 10:38 UTC -
web:www.pcworld.com
This month's Patch Tuesday brings over 80 fixes for various security vulnerabilities. Fortunately, none are actively being exploited in the wild yet.
2026-05-22 10:38 UTC -
web:www.bleepingcomputer.com
Today is Microsoft's March 2026 Patch Tuesday with security updates for 79 flaws, including 2 publicly disclosed zero-day vulnerabilities.
2026-05-22 10:38 UTC -
web:www.oracle.com
This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.
2026-05-22 10:38 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2024-4763.json.
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:o:lenovo:display_control_center:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "display_control_center",
"vendor": "lenovo",
"versions": [
{
"lessThan": "3.0.29082.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:a:lenovo:accessories_and_display_manager:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "accessories_and_display_manager",
"vendor": "lenovo",
"versions": [
{
"lessThan": "1.0.3.05",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-4763",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-08-16T15:02:13.979566Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-08-16T15:08:37.647Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Display Control Center",
"vendor": "Lenovo",
"versions": [
{
"lessThan": "3.0.29082.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Accessories and Display Manager",
"vendor": "Lenovo",
"versions": [
{
"lessThan": "1.0.3.05",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Lenovo thanks Alain R\u00f6del of Neodyme AG for reporting CVE-2024-4763."
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<span style=\"background-color: rgb(255, 255, 255);\">An insecure driver vulnerability was reported in <span style=\"background-color: rgb(255, 255, 255);\">Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM)</span>\n\n that could allow a local attacker to escalate privileges to kernel.</span>"
}
],
"value": "An insecure driver vulnerability was reported in\u00a0Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM)\n\n that could allow a local attacker to escalate privileges to kernel."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-276",
"description": "CWE-276 Incorrect Default Permissions",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-08-16T14:17:13.323Z",
"orgId": "da227ddf-6e25-4b41-b023-0f976dcaca4b",
"shortName": "lenovo"
},
"references": [
{
"url": "https://support.lenovo.com/us/en/product_security/LEN-155486"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<span style=\"background-color: rgb(255, 255, 255);\">Update Lenovo Display Control Center to version 3.0.29082.0 </span><span style=\"background-color: rgb(255, 255, 255);\">or later.</span>\n\n<br>"
}
],
"value": "Update Lenovo Display Control Center to version 3.0.29082.0 or later."
},
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Update Lenovo Accessories and Display Manager to version 1.0.3.05 or later."
}
],
"value": "Update Lenovo Accessories and Display Manager to version 1.0.3.05 or later."
}
],
"source": {
"discovery": "UNKNOWN"
},
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "da227ddf-6e25-4b41-b023-0f976dcaca4b",
"assignerShortName": "lenovo",
"cveId": "CVE-2024-4763",
"datePublished": "2024-08-16T14:17:13.323Z",
"dateReserved": "2024-05-10T16:48:15.261Z",
"dateUpdated": "2024-08-16T15:08:37.647Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}