First published: Tue May 12 2015(Updated: )
Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permissions for the update files directory, which allows local users to gain privileges by writing to an update file after the signature is validated.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo System Update | <=5.06.0027 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2234 has a medium severity rating due to the potential for local privilege escalation.
To fix CVE-2015-2234, upgrade Lenovo System Update to version 5.06.0034 or later.
CVE-2015-2234 affects Lenovo System Update versions prior to 5.06.0034.
Local users on systems running affected versions of Lenovo System Update may be impacted by CVE-2015-2234.
CVE-2015-2234 is caused by a race condition due to world-writable permissions in the update files directory.