Race Condition Vulnerability in Lenovo System Update Software
CVE-2015-7335
7HIGH
Summary
A race condition vulnerability in Lenovo System Update versions up to 5.07.0008 can permit an attacker to exploit the software, potentially allowing arbitrary code execution with elevated privileges. This flaw could be triggered under specific timing conditions, which may be leveraged by malicious actors to gain unauthorized control over an affected system. Users of Lenovo System Update are advised to update to the latest version to mitigate this risk.
References
CVSS V3.1
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved