CVE-2025-12046

7.8

Lenovo · App Store and Browser

Lenovo App Store and Browser applications are vulnerable to DLL hijacking, potentially allowing a local authenticated user to execute code with elevated privileges.

Executive summary

A DLL hijacking vulnerability in Lenovo App Store and Browser applications allows local authenticated users to gain elevated system privileges.

Vulnerability

This vulnerability is classified as an uncontrolled search path element (CWE-427), where the software insecurely loads dynamic link libraries. An authenticated local user can exploit this weakness to execute arbitrary code with elevated permissions.

Business impact

The potential for privilege escalation poses a significant risk to organizational security, as it allows attackers to bypass standard user restrictions and gain deeper access to the local environment. Given the CVSS score of 7.8, this vulnerability is categorized as High severity, indicating that successful exploitation could lead to full system compromise, unauthorized data access, or the deployment of persistent threats within the local host.

Remediation

Immediate Action: Update the Lenovo App Store to version 9.0.2530.1027 or later and the Lenovo Browser to version 9.0.6.11071 or later immediately.

Proactive Monitoring: Monitor system logs for unauthorized process execution or unexpected file system modifications in directories where these applications are installed.

Compensating Controls: Ensure that standard user accounts are restricted from writing to application directories, which limits the ability of an attacker to place malicious DLLs in the search path.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability represents a significant security risk for Lenovo software users due to the potential for privilege escalation. Security teams should prioritize deploying the vendor provided updates to all affected workstations and servers. Failure to patch these applications leaves systems susceptible to local attacks that could result in full administrative control over the host machine.

More Lenovo CVEs

Sources

Originally found and disclosed by Lenovo thanks Wanjie from Huazhong University of Science and Technology for reporting this issue., per the CVE Program record.