CVE-2017-3761
Status: ModifiedCritical (9.8)—
The Lenovo Service Framework Android application executes some system commands without proper sanitization of external input. In certain cases, this could lead to command injection which, in turn, could lead to remote code execution.
CVSS
- Version: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Base score: 9.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 4.21%
- Percentile among all scored CVEs: 91
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-78
References
Raw JSON (NVD)
Show
{
"id": "CVE-2017-3761",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": true,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "psirt@lenovo.com",
"affectedData": [
{
"vendor": "Lenovo Group Ltd.",
"product": "Service Framework application",
"versions": [
{
"status": "affected",
"version": "various versions"
}
]
}
]
}
],
"published": "2017-10-17T20:29:00.370",
"references": [
{
"url": "https://support.lenovo.com/us/en/product_security/LEN-15374",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "psirt@lenovo.com"
},
{
"url": "https://support.lenovo.com/us/en/product_security/LEN-15374",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Lenovo Service Framework Android application executes some system commands without proper sanitization of external input. In certain cases, this could lead to command injection which, in turn, could lead to remote code execution."
},
{
"lang": "es",
"value": "La aplicación Lenovo Service Framework de Android ejecuta algunos comandos de sistema sin sanitizar correctamente las entradas externas. En algunos casos, esto puede provocar una inyección de comandos que, a su vez, puede resultar en una ejecución remota de código."
}
],
"lastModified": "2026-06-17T01:18:52.470",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:lenovo:service_framework:-:*:*:*:*:android:*:*",
"vulnerable": true,
"matchCriteriaId": "4A00A993-C187-471B-B5A4-66B69C86FC6B"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@lenovo.com"
}