Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permissions for the update files directory, which allows local users to gain privileges by writing to an update file after the signature is validated.
References
Configurations
Information
Published : 2015-05-12 12:59
Updated : 2017-01-02 18:59
NVD link : CVE-2015-2234
Mitre link : CVE-2015-2234
JSON object : View
CWE
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Products Affected
lenovo
- system_update