Vulnerability Description
Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permissions for the update files directory, which allows local users to gain privileges by writing to an update file after the signature is validated.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | System Update | <= 5.06.0027 |
Related Weaknesses (CWE)
References
- http://securitytracker.com/id/1032268
- http://support.lenovo.com/us/en/product_security/lsu_privilegeVendor Advisory
- http://www.ioactive.com/pdfs/Lenovo_System_Update_Multiple_Privilege_Escalations
- http://www.securityfocus.com/bid/74634
- http://securitytracker.com/id/1032268
- http://support.lenovo.com/us/en/product_security/lsu_privilegeVendor Advisory
- http://www.ioactive.com/pdfs/Lenovo_System_Update_Multiple_Privilege_Escalations
- http://www.securityfocus.com/bid/74634
FAQ
What is CVE-2015-2234?
CVE-2015-2234 is a vulnerability with a CVSS score of 6.9 (MEDIUM). Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permissions for the update files directory, which allows local users to gain privilege...
How severe is CVE-2015-2234?
CVE-2015-2234 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-2234?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo System Update.