Remote code execution in Lenovo Updates (not Lenovo System Update) allows man-in-the-middle attackers to execute arbitrary code.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://support.lenovo.com/us/en/solutions/LEN-8313 | mitigation vendor advisory |
http://www.securityfocus.com/bid/97560 | vdb entry third party advisory |