s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2024-4763

📛 CVE Title

CVE-2024-4763

Description

An insecure driver vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) that could allow a local attacker to escalate privileges to kernel.

Overview

State
PUBLISHED
Assigner (CNA)
lenovo
CVSS severity
HIGH
CVSS score
CVSS 7.8 / 10 7.8 7.8 / 10
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Effective score
7.8 / 10 HIGH source: CNA overview
CWE(s)
CWE-276
Reserved
2024-05-10
Published
2024-08-16 16:17 UTC
Last updated
2024-08-16 17:08 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/4xxx/CVE-2024-4763.json
Linked Threat
CVE-2024-4763 — CVE-2024-4763

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2024-44359
Assigner
lenovo
Published
Aug 16, 2024, 2:17:13 PM
Updated
Aug 16, 2024, 3:08:37 PM
EUVD base score (CVSS 3.1)
7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EUVD-reported EPSS
0.0500
Vendors
Lenovo
Products
Accessories and Display Manager (0 <1.0.3.05)
Display Control Center (0 <3.0.29082.0)
Aliases
GHSA-5cv5-pc9w-5hgp

ENISA description: An insecure driver vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) that could allow a local attacker to escalate privileges to kernel.

EUVD references (1)

Affected products (2)

VendorProductVersionsPlatforms
Lenovo Display Control Center 0 (affected)
Lenovo Accessories and Display Manager 0 (affected)

Vendor references (1)

References embedded in the original CVE record by the assigning CNA.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

Remediations (18)

Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

  • web:cybernews.com

    Microsoft's July 2026 Patch Tuesday fixes a record 622 vulnerabilities and begins mandatory Kerberos RC4 enforcement, marking one of Windows' biggest security updates.

    2026-08-05 12:57 UTC
  • web:msrc.microsoft.com

    The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.

    2026-08-05 12:57 UTC
  • web:msrc.microsoft.com

    Security Update Guide - Microsoft Security Response Center

    2026-08-05 12:57 UTC
  • web:support.microsoft.com

    Improvements and fixes This security update introduces the SharePoint Server Subscription Edition Version 26H1 feature update. This feature update will be included in all SharePoint Server Subscription Edition public updates going forward. For more information about this feature update, see New and improved features in SharePoint Server Subscription Edition Version 26H1. This link may be ...

    2026-08-05 12:57 UTC
  • web:www.cisa.gov

    The median time for full resolution rose to 43 days. Defenders need greater clarity and speed to patch systems in today's threat landscape. We must flip the script on patching prioritization: patch smarter, not harder.

    2026-08-05 12:57 UTC
  • web:www.microsoft.com

    Microsoft's free Security Update Guide Notifications provide links to security-related software updates and notification of re-released security updates. These notifications are sent via email throughout the month as needed. You can choose the type of updates for which you want to be notified: Major ...

    2026-08-05 12:57 UTC
  • web:www.oracle.com

    Prior Critical Patch Update and Critical Security Patch Update advisories should be reviewed for information regarding earlier published security patches. Refer to Critical Patch Updates, Critical Security Patch Updates, Security Alerts and Bulletins for information about Oracle Security advisories.

    2026-08-05 12:57 UTC
  • web:www.tenable.com

    Microsoft patched 569 CVEs in July 2026, the largest Patch Tuesday release in its history. 56 critical CVEs patched including three zero-day vulnerabilities.

    2026-08-05 12:57 UTC
  • web:www.computerworld.com

    Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...

    2026-05-22 10:38 UTC
  • web:www.crowdstrike.com

    Microsoft's March 2026 Patch Tuesday addresses 82 CVEs , featuring eight Critical vulnerabilities.

    2026-05-22 10:38 UTC
  • web:www.forbes.com

    Microsoft starts expiring critical Secure Boot certificates in just 2 weeks.

    2026-05-22 10:38 UTC
  • web:cybersecuritynews.com

    Microsoft released an out-of-band hotpatch update on March 13, 2026, addressing serious security vulnerabilities in Windows 11 versions 24H2 and 25H2.

    2026-05-22 10:38 UTC
  • web:www.ibm.com

    Updates listed within IBM Fix Central without a key symbol are generally available for installation subject to the terms of the applicable license agreement. Any copying, reproduction, distribution, or installation of code, other than as expressly authorized by IBM, is prohibited.

    2026-05-22 10:38 UTC
  • web:www.maketecheasier.com

    Check out the latest Windows 11 and Windows 10 update problems and their solutions, as recommended by Microsoft experts.

    2026-05-22 10:38 UTC
  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

    2026-05-22 10:38 UTC
  • web:www.pcworld.com

    This month's Patch Tuesday brings over 80 fixes for various security vulnerabilities. Fortunately, none are actively being exploited in the wild yet.

    2026-05-22 10:38 UTC
  • web:www.bleepingcomputer.com

    Today is Microsoft's March 2026 Patch Tuesday with security updates for 79 flaws, including 2 publicly disclosed zero-day vulnerabilities.

    2026-05-22 10:38 UTC
  • web:www.oracle.com

    This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.

    2026-05-22 10:38 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2024-4763.json.

{
  "containers": {
    "adp": [
      {
        "affected": [
          {
            "cpes": [
              "cpe:2.3:o:lenovo:display_control_center:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "product": "display_control_center",
            "vendor": "lenovo",
            "versions": [
              {
                "lessThan": "3.0.29082.0",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:lenovo:accessories_and_display_manager:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "product": "accessories_and_display_manager",
            "vendor": "lenovo",
            "versions": [
              {
                "lessThan": "1.0.3.05",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-4763",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-08-16T15:02:13.979566Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-08-16T15:08:37.647Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Display Control Center",
          "vendor": "Lenovo",
          "versions": [
            {
              "lessThan": "3.0.29082.0",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Accessories and Display Manager",
          "vendor": "Lenovo",
          "versions": [
            {
              "lessThan": "1.0.3.05",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Lenovo thanks Alain R\u00f6del of Neodyme AG for reporting CVE-2024-4763."
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "<span style=\"background-color: rgb(255, 255, 255);\">An insecure driver vulnerability was reported in&nbsp;<span style=\"background-color: rgb(255, 255, 255);\">Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM)</span>\n\n that could allow a local attacker to escalate privileges to kernel.</span>"
            }
          ],
          "value": "An insecure driver vulnerability was reported in\u00a0Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM)\n\n that could allow a local attacker to escalate privileges to kernel."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-276",
              "description": "CWE-276 Incorrect Default Permissions",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2024-08-16T14:17:13.323Z",
        "orgId": "da227ddf-6e25-4b41-b023-0f976dcaca4b",
        "shortName": "lenovo"
      },
      "references": [
        {
          "url": "https://support.lenovo.com/us/en/product_security/LEN-155486"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "<span style=\"background-color: rgb(255, 255, 255);\">Update Lenovo Display Control Center to version 3.0.29082.0 </span><span style=\"background-color: rgb(255, 255, 255);\">or later.</span>\n\n<br>"
            }
          ],
          "value": "Update Lenovo Display Control Center to version 3.0.29082.0 or later."
        },
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "Update Lenovo Accessories and Display Manager to version 1.0.3.05 or later."
            }
          ],
          "value": "Update Lenovo Accessories and Display Manager to version 1.0.3.05 or later."
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "x_generator": {
        "engine": "Vulnogram 0.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "da227ddf-6e25-4b41-b023-0f976dcaca4b",
    "assignerShortName": "lenovo",
    "cveId": "CVE-2024-4763",
    "datePublished": "2024-08-16T14:17:13.323Z",
    "dateReserved": "2024-05-10T16:48:15.261Z",
    "dateUpdated": "2024-08-16T15:08:37.647Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}