Local Privilege Escalation Vulnerability in Lenovo System Update
CVE-2015-8110

7.8HIGH

Key Information:

Vendor
Lenovo
Vendor
CVE Published:
24 April 2017

Summary

The Lenovo System Update application, previously known as ThinkVantage System Update, contains a local privilege escalation vulnerability that allows local users to gain elevated privileges. This issue arises when users interact with the 'Click here to learn more' and 'View privacy policy' options within the Tvsukernel.exe GUI application while operating under a temporary administrator account. This vulnerability could be exploited to perform unauthorized actions on the system, highlighting the need for users to update their systems to the latest version to mitigate the risk.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.