VulnerabilityModified
CVE-2015-3320
Lenovo USB Enhanced Performance Keyboard software before 2.0.2.2 includes active debugging code in SKHOOKS.DLL, which allows local users to obtain keypress information by accessing debug output.
LOW 2.1EPSS 0.32%
Does this matter?
Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.
Description
Lenovo USB Enhanced Performance Keyboard software before 2.0.2.2 includes active debugging code in SKHOOKS.DLL, which allows local users to obtain keypress information by accessing debug output.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.32% probability · 25th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- lenovo/usb enhanced performance keyboard
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/74196Third Party Advisory, VDB Entry
- https://support.lenovo.com/us/en/product_security/usbenhancedkeyboardPatch, Vendor Advisory
- http://www.securityfocus.com/bid/74196Third Party Advisory, VDB Entry
- https://support.lenovo.com/us/en/product_security/usbenhancedkeyboardPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.