CVE-2015-8110: High severity lenovo system update vulnerability
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by navigating to (1) "Click here to learn more" or (2) "View privacy policy" within the Tvsukernel.exe GUI application in the context of a temporary administrator account, aka a "local privilege escalation vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8110?
CVE-2015-8110 has a moderate severity rating due to its potential to allow local privilege escalation.
How do I fix CVE-2015-8110?
To fix CVE-2015-8110, update Lenovo System Update to version 5.07.0019 or later.
Who is affected by CVE-2015-8110?
Local users with temporary administrator accounts are affected by CVE-2015-8110.
What can attackers do with CVE-2015-8110?
Attackers can gain elevated privileges on the system through the vulnerable Lenovo System Update application.
Is CVE-2015-8110 remotely exploitable?
No, CVE-2015-8110 is not remotely exploitable; it requires local access to the system.