High severity7.8NVD Advisory· Published Mar 27, 2020· Updated Jun 17, 2026
CVE-2015-7333
CVE-2015-7333
Description
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior where the SUService.exe /type INF and INF_BY_COMPATIBLE_ID command types could allow a user to execute arbitrary code with elevated privileges.
Affected products
3cpe:2.3:a:lenovo:system_update:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:lenovo:system_update:*:*:*:*:*:*:*:*range: <=5.07.0008
- (no CPE)range: <=5.07.0008
- Lenovo/System Updatedescription
Patches
Vulnerability mechanics
References
1- support.lenovo.com/us/en/product_security/lsu_privilegenvdVendor Advisory
News mentions
0No linked articles in our index yet.