During an internal security review, Lenovo identified a local privilege escalation vulnerability in Lenovo System Interface Foundation software installed on some Windows 10 PCs where a user with local privileges could run arbitrary code with administrator level privileges.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://support.lenovo.com/us/en/solutions/LEN_10150 | patch vendor advisory |
http://www.securityfocus.com/bid/94597 | vdb entry |