QID 378700

Date Published: 2023-08-07

QID 378700: Lenovo System Update Elevation of Privileges Vulnerability (LEN-103545)

A directory permissions management vulnerability in Lenovo System Update may allow elevation of privileges.

Affected Products:
Lenovo System Update prior to version 5.08.01

QID Detection Logic
: This QID looks for the vulnerable version of Lenovo System Update (SUService.exe).

Successful exploitation could allow escalation of privilege.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Users are advised to upgrade to Lenovo System Update 5.08.01 or later

    CVEs related to QID 378700

    Software Advisories
    Advisory ID Software Component Link
    LEN-103545 URL Logo support.lenovo.com/in/en/product_security/LEN-103545