CVE-2015-2219
published 2015-05-12CVE-2015-2219: Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privileges by…
PriorityP339high7.2CVSS 2.0
AVLACLAuNCCICAC
EXPLOIT
EPSS
4.15%
89.7th percentile
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privileges by sending a valid token with a command to the System Update service (SUService.exe) through an unspecified named pipe.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lenovo | system_update | <= 5.06.0027 | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Lenovo System Update - Local Privilege Escalation (Metasploit)
exploitdb·2015-04-12
CVE-2015-2219 Lenovo System Update - Local Privilege Escalation (Metasploit)
Lenovo System Update - Local Privilege Escalation (Metasploit)
---
##
# This module requires Metasploit: http://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule 'Lenovo System Update Privilege Escalation',
'Description' => %q{
The named pipe, \SUPipeServer, can be accessed by normal users to interact with the
System update service. The service provides the possibility to execute arbitrary
commands as SYSTEM if a valid security token is provided. This token can be generated
by calling the GetSystemInfoData function in the DLL tvsutil.dll. Please, note that the
System Update is stopped by default but can be started/stopped calling the Executable
ConfigService.exe.
},
'License' => MSF_LICENSE,
'Author' =>
[
'Michael Milvich'
Metasploit
Lenovo System Update Privilege Escalation
metasploit
Lenovo System Update Privilege Escalation
Lenovo System Update Privilege Escalation
The named pipe, \SUPipeServer, can be accessed by normal users to interact with the System update service. The service provides the possibility to execute arbitrary commands as SYSTEM if a valid security token is provided. This token can be generated by calling the GetSystemInfoData function in the DLL tvsutil.dll. Please, note that the System Update is stopped by default but can be started/stopped calling the Executable ConfigService.exe.
No writeups or analysis indexed.
http://securitytracker.com/id/1032268http://support.lenovo.com/us/en/product_security/lsu_privilegehttp://www.ioactive.com/pdfs/Lenovo_System_Update_Multiple_Privilege_Escalations.pdfhttp://www.securityfocus.com/bid/74649http://securitytracker.com/id/1032268http://support.lenovo.com/us/en/product_security/lsu_privilegehttp://www.ioactive.com/pdfs/Lenovo_System_Update_Multiple_Privilege_Escalations.pdfhttp://www.securityfocus.com/bid/74649
2015-05-12
Published