CVE-2015-7334: Lenovo System Update

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior where the SUService.exe /type COMMAND type could allow a user to execute arbitrary code with elevated privileges.

Affected products

  • Lenovo System Update: up to and including 5.07.0008

Published 2020-03-27. Last modified 2026-06-17.