VYPR
High severity7.8NVD Advisory· Published Mar 27, 2020· Updated Jun 17, 2026

CVE-2015-7333

CVE-2015-7333

Description

MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior where the SUService.exe /type INF and INF_BY_COMPATIBLE_ID command types could allow a user to execute arbitrary code with elevated privileges.

Affected products

3
  • cpe:2.3:a:lenovo:system_update:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:lenovo:system_update:*:*:*:*:*:*:*:*range: <=5.07.0008
    • (no CPE)range: <=5.07.0008
  • Lenovo/System Updatedescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.