First published: Mon Apr 24 2017(Updated: )
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by navigating to (1) "Click here to learn more" or (2) "View privacy policy" within the Tvsukernel.exe GUI application in the context of a temporary administrator account, aka a "local privilege escalation vulnerability."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo System Update | <=5.07.0013 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8110 has a moderate severity rating due to its potential to allow local privilege escalation.
To fix CVE-2015-8110, update Lenovo System Update to version 5.07.0019 or later.
Local users with temporary administrator accounts are affected by CVE-2015-8110.
Attackers can gain elevated privileges on the system through the vulnerable Lenovo System Update application.
No, CVE-2015-8110 is not remotely exploitable; it requires local access to the system.