VulnerabilityModified
CVE-2016-5248
The StopProxy command in LSC.Services.SystemService in Lenovo Solution Center before 3.3.003 allows local users to terminate arbitrary processes via the PID argument.
MEDIUM 5.5EPSS 0.30%
Does this matter?
Lower severity and a low EPSS score (0.30%). Track it; it rarely justifies an emergency change on its own.
Description
The StopProxy command in LSC.Services.SystemService in Lenovo Solution Center before 3.3.003 allows local users to terminate arbitrary processes via the PID argument.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.30% probability · 23th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- lenovo/solution center
- Source
- cve@mitre.org
References
- https://support.lenovo.com/us/en/product_security/len_7814Vendor Advisory
- https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2016-012/?fid=8073
- https://support.lenovo.com/us/en/product_security/len_7814Vendor Advisory
- https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2016-012/?fid=8073
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.