First published: Tue May 12 2015(Updated: )
Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permissions for the update files directory, which allows local users to gain privileges by writing to an update file after the signature is validated.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo System Update | <=5.06.0027 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.