KLA10812
Privilege escalation vulnerabilities in Lenovo Solution Center
Обновлено: 17/06/2019
Дата обнаружения
22/06/2016
Уровень угрозы
High
Описание

Multiple serious vulnerabilities have been found in Lenovo Solution Center. Malicious users can exploit these vulnerabilities to gain privileges.

Below is a complete list of vulnerabilities

  1. An unknown vulnerability at SystemService can be exploited locally to terminate arbitrary process via StopProxy command;
  2. An unknown vulnerability at SystemService can be exploited locally via StartProxy command to conduct execute arbitrary code with LocalSystem privileges.
Пораженные продукты

Lenovo Solution Center versions earlier than 3.3.003

Решение

Install update via Lenovo Solution Center, Lenovo System Update or manually. Instructions for update can be found at original advisory
Download update

Первичный источник обнаружения
Lenovo advisory
Оказываемое влияние
?
PE 
[?]
CVE-IDS