Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permissions for the update files directory, which allows local users to gain privileges by writing to an update file after the signature is validated.
References
Configurations
History
21 Nov 2024, 02:27
Type | Values Removed | Values Added |
---|---|---|
References | () http://securitytracker.com/id/1032268 - | |
References | () http://support.lenovo.com/us/en/product_security/lsu_privilege - Vendor Advisory | |
References | () http://www.ioactive.com/pdfs/Lenovo_System_Update_Multiple_Privilege_Escalations.pdf - | |
References | () http://www.securityfocus.com/bid/74634 - |
Information
Published : 2015-05-12 19:59
Updated : 2024-11-21 02:27
NVD link : CVE-2015-2234
Mitre link : CVE-2015-2234
CVE.ORG link : CVE-2015-2234
JSON object : View
Products Affected
lenovo
- system_update
CWE
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')