CVE-2015-2219: High severity lenovo system update vulnerability
Published May 12, 2015
·Updated
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privileges by sending a valid token with a command to the System Update service (SUService.exe) through an unspecified named pipe.
Affected Software
1 affected component
Lenovo System Update<=5.06.0027
Event History
May 12, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2219?
CVE-2015-2219 has been assigned a medium severity rating due to its potential for privilege escalation.
2
How do I fix CVE-2015-2219?
To fix CVE-2015-2219, upgrade Lenovo System Update to version 5.06.0034 or later.
3
Who is affected by CVE-2015-2219?
Local users of Lenovo System Update versions prior to 5.06.0034 are affected by CVE-2015-2219.
4
What causes CVE-2015-2219?
CVE-2015-2219 is caused by the use of predictable security tokens in Lenovo System Update.
5
What systems are vulnerable to CVE-2015-2219?
All versions of Lenovo System Update before 5.06.0034 are vulnerable to CVE-2015-2219.