CVE-2015-2234: Lenovo System Update

Medium severity, CVSS 6.9. EPSS: 0.3% chance of exploitation in the next 30 days.

Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permissions for the update files directory, which allows local users to gain privileges by writing to an update file after the signature is validated.

Affected products

  • Lenovo System Update: up to and including 5.06.0027

Published 2015-05-12. Last modified 2026-06-17.