{"id":"CVE-2026-1652","title":"A potential buffer overflow vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated user to corrupt memory and cause a Windows blue screen error.","summary":"A potential buffer overflow vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated user to corrupt memory and cause a Windows blue screen error.","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H","cwe":["CWE-122"],"vendor":"lenovo","product":"smart_connect","affected":["smart_connect < 09.0.1.002.000"],"patched":["smart_connect 09.0.1.002.000"],"published":"2026-03-11","updated":"2026-08-20","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-1652","references":[{"url":"https://support.lenovo.com/us/en/product_security/LEN-209683","label":"psirt@lenovo.com"}],"tags":["nvd"],"epss":0.00094,"epssPercentile":0.00708,"ingestedAt":"2026-08-20T17:59:04.510Z","slug":"CVE-2026-1652","body":"## Overview\n\nA potential buffer overflow vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated user to corrupt memory and cause a Windows blue screen error.\n\n## Affected\n\n- `smart_connect < 09.0.1.002.000`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `smart_connect 09.0.1.002.000`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}