Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by making a prediction of tvsu_tmp_xxxxxXXXXX account credentials that requires knowledge of the time that this account was created, aka a "temporary administrator account vulnerability."
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/98039 | vdb entry |
https://ioactive.com/pdfs/IOActive_Advisory_Lenovo_SystemUpdate-Insecure-Random-Admin-Password.pdf | third party advisory exploit |
https://support.lenovo.com/us/en/product_security/lsu_privilege | vendor advisory |