CVE-2015-7335: Race Condition
Published Mar 27, 2020
·Updated
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A race condition was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow a user to execute arbitrary code with elevated privileges.
Affected Software
1 affected component
Lenovo System Update<=5.07.0008
Event History
Mar 27, 2020
CVE Published
via MITRE·02:05 PM
Data Sourced
via MITRE·02:05 PM
Description
Frequently Asked Questions
1
What is CVE-2015-7335?
CVE-2015-7335 is a race condition vulnerability in Lenovo System Update version 5.07.0008 and prior.
2
How severe is CVE-2015-7335?
CVE-2015-7335 has a severity rating of high, with a severity value of 7.
3
How can CVE-2015-7335 be exploited?
CVE-2015-7335 can be exploited by an attacker to execute arbitrary code with elevated privileges.
4
Which software versions are affected by CVE-2015-7335?
Lenovo System Update version 5.07.0008 and prior are affected by CVE-2015-7335.
5
How can I fix CVE-2015-7335?
To fix CVE-2015-7335, it is recommended to update Lenovo System Update to a version newer than 5.07.0008.