CVE-2015-2233: Lenovo System Update

High severity, CVSS 8.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during signature validation, which allows man-in-the-middle attackers to upload and execute arbitrary files via a crafted certificate.

Affected products

  • Lenovo System Update: up to and including 5.06.0027

Published 2015-05-12. Last modified 2026-06-17.