CVE-2015-8110

Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by navigating to (1) "Click here to learn more" or (2) "View privacy policy" within the Tvsukernel.exe GUI application in the context of a temporary administrator account, aka a "local privilege escalation vulnerability."
Configurations

Configuration 1 (hide)

cpe:2.3:a:lenovo:lenovo_system_update:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:38

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/98037 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/98037 - Third Party Advisory, VDB Entry
References () https://ioactive.com/pdfs/IOActive_Advisory_Lenovo_TVSUkernel-Escalation-Privileges.pdf - Exploit, Third Party Advisory () https://ioactive.com/pdfs/IOActive_Advisory_Lenovo_TVSUkernel-Escalation-Privileges.pdf - Exploit, Third Party Advisory
References () https://support.lenovo.com/us/en/product_security/lsu_privilege - Vendor Advisory () https://support.lenovo.com/us/en/product_security/lsu_privilege - Vendor Advisory

Information

Published : 2017-04-24 06:59

Updated : 2024-11-21 02:38


NVD link : CVE-2015-8110

Mitre link : CVE-2015-8110

CVE.ORG link : CVE-2015-8110


JSON object : View

Products Affected

lenovo

  • lenovo_system_update
CWE
CWE-264

Permissions, Privileges, and Access Controls