CVE-2015-7333: Lenovo System Update
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior where the SUService.exe /type INF and INF_BY_COMPATIBLE_ID command types could allow a user to execute arbitrary code with elevated privileges.
Affected products
- Lenovo System Update: up to and including 5.07.0008
Published 2020-03-27. Last modified 2026-06-17.