MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A race condition was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow a user to execute arbitrary code with elevated privileges.
References
Link | Resource |
---|---|
https://support.lenovo.com/us/en/product_security/lsu_privilege | Vendor Advisory |
Configurations
Information
Published : 2020-03-27 08:15
Updated : 2020-03-30 11:23
NVD link : CVE-2015-7335
Mitre link : CVE-2015-7335
JSON object : View
CWE
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Products Affected
lenovo
- system_update