Local Privilege Escalation Vulnerability in Lenovo System Update
CVE-2015-8110
7.8HIGH
Summary
The Lenovo System Update application, previously known as ThinkVantage System Update, contains a local privilege escalation vulnerability that allows local users to gain elevated privileges. This issue arises when users interact with the 'Click here to learn more' and 'View privacy policy' options within the Tvsukernel.exe GUI application while operating under a temporary administrator account. This vulnerability could be exploited to perform unauthorized actions on the system, highlighting the need for users to update their systems to the latest version to mitigate the risk.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved