KLA10812
Privilege escalation vulnerabilities in Lenovo Solution Center
Updated: 06/01/2019
Detect date
?
06/22/2016
Severity
?
High
Description

Multiple serious vulnerabilities have been found in Lenovo Solution Center. Malicious users can exploit these vulnerabilities to gain privileges.

Below is a complete list of vulnerabilities

  1. An unknown vulnerability at SystemService can be exploited locally to terminate arbitrary process via StopProxy command;
  2. An unknown vulnerability at SystemService can be exploited locally via StartProxy command to conduct execute arbitrary code with LocalSystem privileges.
Affected products

Lenovo Solution Center versions earlier than 3.3.003

Solution

Install update via Lenovo Solution Center, Lenovo System Update or manually. Instructions for update can be found at original advisory
Download update

Original advisories

Lenovo advisory

Impacts
?
PE 
[?]
CVE-IDS
?