An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to perform an arbitrary file deletion with elevated privileges.
Update VantageCoreAddin to version 1.1.0.51 or later. VantageCoreAddin is updated automatically.