Lenovo
Lenovo System Update: vulnerabilidades y CVE
Lenovo System Update tiene 16 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses1
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-6387 | Alta (7.3) | 0.18% | — | 13 ago 2026 | A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary code with elevated privileges. |
| CVE-2023-4632 | Alta (7.8) | 0.32% | — | 8 nov 2023 | An uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access to execute code with elevated privileges. |
| CVE-2022-4568 | Alta (7.8) | 0.19% | — | 1 may 2023 | A directory permissions management vulnerability in Lenovo System Update may allow elevation of privileges. |
| CVE-2022-0354 | Alta (7.8) | 0.26% | — | 22 abr 2022 | A vulnerability was reported in Lenovo System Update that could allow a local user with interactive system access the ability to execute code with elevated privileges only during the installation of a System Update… |
| CVE-2020-8342 | Alta (7) | 0.22% | — | 15 sept 2020 | A race condition vulnerability was reported in Lenovo System Update prior to version 5.07.0106 that could allow escalation of privilege. |
| CVE-2015-7336 | Alta (7.5) | 0.59% | — | 27 mar 2020 | MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could… |
| CVE-2015-7335 | Alta (7) | 0.23% | — | 27 mar 2020 | MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A race condition was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could… |
| CVE-2015-7334 | Alta (7.8) | 0.36% | — | 27 mar 2020 | MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version… |
| CVE-2015-7333 | Alta (7.8) | 0.35% | — | 27 mar 2020 | MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version… |
| CVE-2019-6175 | Alta (7.5) | 1.7% | — | 26 sept 2019 | A denial of service vulnerability was reported in Lenovo System Update versions prior to 5.07.0088 that could allow configuration files to be written to non-standard locations. |
| CVE-2019-6163 | Alta (7.5) | 0.84% | — | 26 jun 2019 | A denial of service vulnerability was reported in Lenovo System Update before version 5.07.0084 that could allow service log files to be written to non-standard locations. |
| CVE-2018-9063 | Alta (7.8) | 0.39% | — | 4 may 2018 | MapDrv (C:\Program Files\Lenovo\System Update\mapdrv.exe) In Lenovo System Update versions earlier than 5.07.0072 contains a local vulnerability where an attacker entering very large user ID or password can overrun the… |
| CVE-2015-6971 | Alta (7.8) | 0.47% | — | 3 oct 2017 | Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0013 allows local users to submit commands to the System Update service (SUService.exe) and gain privileges by launching signed Lenovo executables. |
| CVE-2015-2234 | Media (6.9) | 0.27% | — | 12 may 2015 | Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permissions for the update files directory, which allows local users to gain privileges by writing to an… |
| CVE-2015-2233 | Alta (8.3) | 0.40% | — | 12 may 2015 | Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during signature validation, which allows man-in-the-middle attackers to upload and execute arbitrary… |
| CVE-2015-2219 | Alta (7.2) | 4.1% | — | 12 may 2015 | Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privileges by sending a valid token with a command to the System Update… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Lenovo
Xclarity Administrator · 28Thinkcentre M625q Firmware · 28Thinkcentre M75n Firmware · 27Ideacentre G5-14imb05 Firmware · 27V50t-13imb Firmware · 27Ideacentre 5-14iob6 Firmware · 27Ideacentre Gaming 5-14iob6 Firmware · 27Thinkcentre M75t GEN 2 Firmware · 26V30a-22iml Firmware · 26Ideacentre 3-07imb05 Firmware · 26Ideacentre Creator 5-14iob6 Firmware · 26Ideacentre C5-14imb05 Firmware · 26