PT-2017-6666 · Lenovo · Lenovo Fingerprint Manager

Published

2017-10-02

·

Updated

2017-10-17

·

CVE-2015-3321

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Lenovo Fingerprint Manager versions prior to 8.01.42
Description The issue arises from incorrect Access Control Lists (ACLs) applied to services and files in the Lenovo Fingerprint Manager. This incorrect configuration allows local users to bypass local security checks, potentially gaining elevated privileges through standard file system operations.
Recommendations For versions prior to 8.01.42, update to version 8.01.42 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-3321

Affected Products

Lenovo Fingerprint Manager