Please note: This website includes an accessibility system. Press Control-F11 to adjust the website to the visually impaired who are using a screen reader; Press Control-F10 to open an accessibility menu.

Lenovo System Update Elevation of Privileges Vulnerability

Lenovo System Update Elevation of Privileges Vulnerability

Lenovo System Update Elevation of Privileges Vulnerability

Lenovo Security Advisory: LEN-103545

Potential Impact: Privilege Escalation

Severity: High

Scope of Impact: Lenovo-specific

CVE Identifier: CVE-2022-4568

 

Summary Description:

A directory permissions management vulnerability in Lenovo System Update may allow elevation of privileges.

 

Mitigation Strategy for Customers (what you should do to protect yourself):

Customers should update the Lenovo System Update application to version 5.08.01 or later

Consumer Customers:

https://support.lenovo.com/us/en/solutions/ht037099#tvsu

Enterprise and Commercial Customers:

https://support.lenovo.com/us/en/downloads/ds012808-lenovo-system-update-for-windows-10-7-32-bit-64-bit-desktop-notebook-workstation

 

Acknowledgement:

Lenovo thanks Raphael Rosenast of Compass Security

 

Revision History:

Revision Date Description
1 2023-03-14 Initial release

For a complete list of all Lenovo Product Security Advisories, click here.

For the most up to date information, please remain current with updates and advisories from Lenovo regarding your equipment and software. The information provided in this advisory is provided on an “as is” basis without any warranty or guarantee of any kind. Lenovo reserves the right to change or update this advisory at any time.


Alias Id:LEN-103545
Document ID:PS500553
Original Publish Date:03/14/2023
Last Modified Date:03/14/2023