CVE-2015-8110
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by navigating to (1) "Click here to learn more" or (2) "View privacy policy" within the Tvsukernel.exe GUI application in the context of a temporary administrator account, aka a "local privilege escalation vulnerability."
Lenovo System Update (antes ThinkVantage System Update) en versiones anteriores a 5.07.0019 permite a usuarios locales obtener privilegios navegando a (1) "Haz clic aquí para obtener más información" o (2) "Ver política de privacidad" dentro de la aplicación GUI de Tvsukernel.exe en el contexto de una cuenta de administrador temporal, vulnerabilidad también conocida como "vulnerabilidad de escalamiento de privilegios locales".
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-11-11 CVE Reserved
- 2017-04-24 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/98037 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://ioactive.com/pdfs/IOActive_Advisory_Lenovo_TVSUkernel-Escalation-Privileges.pdf | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.lenovo.com/us/en/product_security/lsu_privilege | 2017-04-28 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Lenovo Search vendor "Lenovo" | Lenovo System Update Search vendor "Lenovo" for product "Lenovo System Update" | <= 5.07.0013 Search vendor "Lenovo" for product "Lenovo System Update" and version " <= 5.07.0013" | - |
Affected
|