First published: Mon Apr 24 2017(Updated: )
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by making a prediction of tvsu_tmp_xxxxxXXXXX account credentials that requires knowledge of the time that this account was created, aka a "temporary administrator account vulnerability."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo System Update | <=5.07.0013 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8109 is classified as a high-severity vulnerability due to its potential for local privilege escalation.
To fix CVE-2015-8109, update Lenovo System Update to version 5.07.0019 or later.
CVE-2015-8109 affects users of Lenovo System Update versions prior to 5.07.0019.
CVE-2015-8109 is a local privilege escalation vulnerability affecting the temporary administrator account.
No, CVE-2015-8109 can only be exploited by local users with access to the system.