CVE-2016-8237: Lenovo Updates

High severity, CVSS 8.1. EPSS: 3.3% chance of exploitation in the next 30 days.

Remote code execution in Lenovo Updates (not Lenovo System Update) allows man-in-the-middle attackers to execute arbitrary code.

Affected products

  • Lenovo Updates: affected versions not specified

Published 2017-04-10. Last modified 2026-06-17.