Lucene search

K
lenovoLenovoLENOVO:PS500076-LENOVO-SYSTEM-INTERFACE-FOUNDATION-PRIVILEGE-ESCALATION-NOSID
HistoryNov 17, 2016 - 12:00 a.m.

Lenovo System Interface Foundation Privilege Escalation - Lenovo Support US

2016-11-1700:00:00
support.lenovo.com
5

0.0004 Low

EPSS

Percentile

5.1%

Lenovo Security Advisory: LEN-10150

Potential Impact: Local privilege escalation

Severity: High

**Scope of Impact:**Lenovo specific

**CVE Identifier:**CVE-2016-8223

Summary Description:

During an internal security review, Lenovo identified a local privilege escalation vulnerability in Lenovo System Interface Foundation software installed on some Windows 10 PCs where a user with local privileges could run arbitrary code with administrator level privileges.

Lenovo System Interface Foundation (which runs in Windows Task Manager as a service called Lenovo.Modern.ImController.exe or Lenovo.Modern.ImController.PluginHost.exe) is a Lenovo-developed software utility that provides system level functionality such as services, drivers and helper applications to other Lenovo software apps and services on Windows 10 systems, including Lenovo Companion, Lenovo Settings and Lenovo ID.

Mitigation Strategy for Customers (what you should do to protect yourself):

Update to the latest version of Lenovo System Interface Foundation (version 1.0.67.0 or later). This will be done automatically as of October 18, 2016 unless users have manually disabled automatic updates. Users can also manually update by downloading the version at the link below:

<http://support.lenovo.com/downloads/ds105970&gt;

To check your version of Lenovo System Interface Foundation, follow the steps below:

  1. Press the Windows Logo key and type “Programs and Features”
  2. Click on “Programs and Features” in the Control Panel
  3. Scroll down the list to find Lenovo System Interface Foundation
  4. The version installed will be displayed to the right under the Version column

0.0004 Low

EPSS

Percentile

5.1%

Related for LENOVO:PS500076-LENOVO-SYSTEM-INTERFACE-FOUNDATION-PRIVILEGE-ESCALATION-NOSID