First published: Mon Oct 02 2017(Updated: )
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0013 allows local users to submit commands to the System Update service (SUService.exe) and gain privileges by launching signed Lenovo executables.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo System Update | <=5.06.0034 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6971 is classified as a privilege escalation vulnerability.
To fix CVE-2015-6971, update the Lenovo System Update to version 5.07.0013 or later.
CVE-2015-6971 affects Lenovo System Update versions prior to 5.07.0013.
Local users with access to the affected Lenovo System Update are vulnerable to CVE-2015-6971.
An attacker exploiting CVE-2015-6971 can submit unauthorized commands and gain elevated privileges.