CVE-2025-0886

7.8

Lenovo · Elliptic Virtual Lock Sensor / Human Presence Detection Driver

An incorrect permissions vulnerability in the Lenovo Elliptic Virtual Lock Sensor allows a local, authenticated user to escalate privileges.

Executive summary

A high-severity privilege escalation vulnerability affects specific Lenovo ThinkPad models, enabling local authenticated users to gain elevated system permissions.

Vulnerability

This vulnerability is caused by incorrect default permissions (CWE-276) within the sensor service and driver components. It allows a local user who has already authenticated to the operating system to execute actions with higher privileges than intended.

Business impact

The CVSS score of 7.8 identifies this as a high-severity risk. Successful exploitation allows a malicious actor with local access to bypass security boundaries, potentially leading to full system compromise, unauthorized data access, or the installation of persistent malicious software.

Remediation

Immediate Action: Update the Elliptic Virtual Lock Sensor and Human Presence Detection drivers to the versions specified in the official Lenovo security advisory (LEN-182738).

Proactive Monitoring: Review system logs for unauthorized attempts to access sensitive service directories or unusual privilege changes associated with the affected driver processes.

Compensating Controls: Restrict local access to critical hardware and workstations to authorized personnel only, as this vulnerability requires local user access to initiate the exploit.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in a GitHub repository.

Analyst recommendation

The risk posed by local privilege escalation on high-performance workstations like the ThinkPad P1 and P14s series is significant. Administrators should prioritize the deployment of the updated drivers provided by Lenovo to close this security gap and prevent unauthorized escalation of privileges.

More Lenovo CVEs

Sources

Originally found and disclosed by Lenovo thanks Alexander Staalgaard, JN Data Red Team, for reporting this issue., per the CVE Program record.