First published: Thu Apr 16 2015(Updated: )
Lenovo USB Enhanced Performance Keyboard software before 2.0.2.2 includes active debugging code in SKHOOKS.DLL, which allows local users to obtain keypress information by accessing debug output.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo USB Enhanced Performance Keyboard | <=2.0.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3320 is classified as a high severity vulnerability because it allows local users to retrieve sensitive information through debugging code.
To fix CVE-2015-3320, upgrade the Lenovo USB Enhanced Performance Keyboard software to version 2.0.2.2 or later.
CVE-2015-3320 affects Lenovo USB Enhanced Performance Keyboard software versions prior to 2.0.2.2.
CVE-2015-3320 is a local privilege escalation vulnerability due to improper handling of debug information.
Local users with access to the system can be affected by CVE-2015-3320, as they may exploit the debugging code to capture keypress data.