CVE-2015-2234

Lenovo System Update < 5.06.0027 - Privilege Escalation via Race Condition in Update Files Directory

Title source: llm
STIX 2.1

Description

Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permissions for the update files directory, which allows local users to gain privileges by writing to an update file after the signature is validated.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/74634
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id/1032268

Scores

EPSS 0.0003
EPSS Percentile 7.9%

Details

CWE
CWE-362
Status published
Products (1)
lenovo/system_update < 5.06.0027
Published May 12, 2015
Tracked Since Feb 18, 2026