CVE-2025-10495

7.5

Lenovo · PC Manager, App Store, Browser, and Legion Zone

Multiple Lenovo client applications contain an improper certificate validation vulnerability that could allow an attacker on the same logical network to execute arbitrary code.

Executive summary

A vulnerability in several Lenovo client applications allows unauthenticated attackers on a local network to achieve remote code execution due to improper certificate validation.

Vulnerability

This vulnerability involves improper certificate validation, categorized as CWE-295, which permits an unauthenticated attacker positioned on the same logical network to intercept or manipulate communications and execute arbitrary code.

Business impact

The ability for an attacker to execute arbitrary code on end-user systems presents a severe risk of full system compromise, data theft, and lateral movement within the corporate network. With a CVSS score of 7.5, this high-severity flaw necessitates immediate attention to prevent potential ransomware deployment or persistent unauthorized access to sensitive hardware environments.

Remediation

Immediate Action: Update the affected Lenovo client applications to the versions specified in the vendor advisory: Lenovo App Store (9.0.2530.1027 or later) and Lenovo PC Manager (5.1.140.9262 or later).

Proactive Monitoring: Monitor network traffic for unusual patterns or unexpected connection attempts originating from Lenovo client software to unauthorized or suspicious endpoints.

Compensating Controls: Implement network segmentation to isolate vulnerable client devices from untrusted network segments and utilize endpoint detection and response tools to identify unauthorized process executions.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations should prioritize the deployment of the provided vendor patches across all managed Lenovo workstations to eliminate the risk of remote code execution. Given the potential for total system compromise, verify that automated update mechanisms are functioning correctly or push the updates via centralized management software immediately.

More Lenovo CVEs

Sources

Originally found and disclosed by Lenovo thanks Wanjie from Huazhong University of Science and Technology for reporting this issue., per the CVE Program record.