CVE-2015-7336: Lenovo System Update

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow the signature check of an update to be bypassed.

Affected products

  • Lenovo System Update: up to and including 5.07.0008

Published 2020-03-27. Last modified 2026-06-17.