CVE-2015-6971: Lenovo System Update

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0013 allows local users to submit commands to the System Update service (SUService.exe) and gain privileges by launching signed Lenovo executables.

Affected products

  • Lenovo System Update: up to and including 5.06.0034

Published 2017-10-03. Last modified 2026-06-17.