CVE-2015-2234: Race Condition
Published May 12, 2015
·Updated
Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permissions for the update files directory, which allows local users to gain privileges by writing to an update file after the signature is validated.
Affected Software
1 affected component
Lenovo System Update<=5.06.0027
Event History
May 12, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2234?
CVE-2015-2234 has a medium severity rating due to the potential for local privilege escalation.
2
How do I fix CVE-2015-2234?
To fix CVE-2015-2234, upgrade Lenovo System Update to version 5.06.0034 or later.
3
Which versions of Lenovo System Update are affected by CVE-2015-2234?
CVE-2015-2234 affects Lenovo System Update versions prior to 5.06.0034.
4
Who is impacted by CVE-2015-2234?
Local users on systems running affected versions of Lenovo System Update may be impacted by CVE-2015-2234.
5
What causes CVE-2015-2234?
CVE-2015-2234 is caused by a race condition due to world-writable permissions in the update files directory.