First published: Tue May 12 2015(Updated: )
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during signature validation, which allows man-in-the-middle attackers to upload and execute arbitrary files via a crafted certificate.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo System Update | <=5.06.0027 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2233 has been assigned a medium severity level due to its potential for man-in-the-middle attacks.
To fix CVE-2015-2233, you should upgrade Lenovo System Update to version 5.06.0034 or later.
CVE-2015-2233 can enable man-in-the-middle attacks that allow unauthorized file uploads and execution.
CVE-2015-2233 affects Lenovo System Update versions prior to 5.06.0034.
Yes, users must update their Lenovo System Update software to mitigate the risk associated with CVE-2015-2233.