CVE-2015-2233: Lenovo System Update
High severity, CVSS 8.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during signature validation, which allows man-in-the-middle attackers to upload and execute arbitrary files via a crafted certificate.
Affected products
- Lenovo System Update: up to and including 5.06.0027
Published 2015-05-12. Last modified 2026-06-17.