An unquoted service path vulnerability in Lenovo LegionSpace version 1.7.11.2 could allow a local attacker to escalate privileges on affected Windows systems.
The issue, discovered by CENACIF-MX and disclosed in December 2025, affects the DAService component. When Windows resolves the service path C:\Program Files\Lenovo\LegionSpace\1.7.11.2\LSDaemon.exe, the unquoted path creates an opportunity for an attacker to plant a malicious executable at a higher position in the search order.
The service runs as LocalSystem, meaning any code planted in the execution path would inherit those elevated privileges. A successful exploit requires the local user to be able to write to a directory earlier in the resolution chain — typically undetected by the OS or security applications.
Lenovo was notified the same day the vulnerability was discovered. A fix shipped on February 9, 2026 with version 1.8.12.13.
If you’re still running LegionSpace 1.7.11.2, updating should be a priority. This is a local privilege escalation — not remotely exploitable — but it’s exactly the kind of foothold an attacker looks for after initial access.
