CVE-2015-3321
medium
CVSS v3
6.7
CVSS v2
7.2
VIR risk
6.7
Description
Services and files in Lenovo Fingerprint Manager before 8.01.42 have incorrect ACLs, which allows local users to invalidate local checks and gain privileges via standard filesystem operations.
Predictions
Exploit likelihood
66%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://support.lenovo.com/us/en/product_security/lenovo_fpr
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| lenovo | fingerprint_manager | {"endIncluding":"8.01.41"} | |
References
CWEs
CWE-264
Verify integrity in audit chain (admin only). AS-IS.