Lucene search

K
lenovoLenovoLENOVO:PS500347-NOSID
HistorySep 06, 2020 - 7:31 p.m.

Lenovo System Update Vulnerability - Lenovo Support US

2020-09-0619:31:28
support.lenovo.com
12

0.0004 Low

EPSS

Percentile

12.6%

**Lenovo Security Advisory:**LEN-42150

**Potential Impact:**Privilege escalation

**Severity:**High

**Scope of Impact:**Lenovo-specific

**CVE Identifier:**CVE-2020-8342

Summary Description:

A race condition vulnerability was reported in Lenovo System Update that could allow escalation of privilege.

Mitigation Strategy for Customers (what you should do to protect yourself):

Upgrade to the Lenovo System Update version 5.07.0106 (or newer).

Acknowledgement:

Lenovo thanks Security Advisor, Anders Kusk, Improsec ApS for reporting this issue.

Revision History:

Revision Date Description
1 2020-09-08 Initial release

For a complete list of all Lenovo Product Security Advisories, click here.

For the most up to date information, please remain current with updates and advisories from Lenovo regarding your equipment and software. The information provided in this advisory is provided on an β€œas is” basis without any warranty or guarantee of any kind. Lenovo reserves the right to change or update this advisory at any time.

0.0004 Low

EPSS

Percentile

12.6%

Related for LENOVO:PS500347-NOSID