CVE-2015-2219
published 2015-05-12CVE-2015-2219: Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privileges by…
high7.2CVSS 3.1
AVLACLAuNCCICAC
EXPLOIT
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privileges by sending a valid token with a command to the System Update service (SUService.exe) through an unspecified named pipe.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lenovo | system_update | <= 5.06.0027 | — |