CVE-2025-8061

7.0

Lenovo · Dispatcher 3

An insufficient access control vulnerability in Lenovo Dispatcher 3.0 and 3.1 drivers allows an authenticated local user to execute code with elevated privileges.

Executive summary

A high-severity local privilege escalation vulnerability in Lenovo Dispatcher drivers, identified as CVE-2025-8061, poses a significant risk to system integrity if exploited by an authenticated user.

Vulnerability

The flaw is categorized as an exposed IOCTL with insufficient access control (CWE-782), which permits an authenticated local user to perform unauthorized actions with elevated privileges.

Business impact

Successful exploitation of this vulnerability allows a local user to gain higher privileges on the host system, potentially leading to full system compromise. With a CVSS score of 7.0, this represents a significant security risk for organizations, as an attacker could bypass standard security boundaries to install malware, access sensitive data, or disable security software.

Remediation

Immediate Action: Update the affected Lenovo Dispatcher drivers to version 3.1.0.41 or newer, as specified in the official Lenovo security advisory.

Proactive Monitoring: Ensure that the Windows feature Core Isolation Memory Integrity is enabled across all fleet devices, as this configuration effectively mitigates the risk of this vulnerability.

Compensating Controls: Restrict local user account permissions and enforce the principle of least privilege to minimize the potential impact if a local account is compromised.

Exploitation status

Public Exploit Available: Yes, multiple public proofs-of-concept are available on GitHub.

Analyst recommendation

Given the availability of public proof-of-concept code and the potential for full system compromise, IT administrators should prioritize the deployment of the driver update provided by Lenovo. If immediate patching is not feasible, verifying that Core Isolation Memory Integrity is enabled on all endpoints remains a critical and highly effective defensive measure.

More Lenovo CVEs

Sources

Originally found and disclosed by Lenovo thanks YiShun Zeng and Luis Casvella of Quarkslab for independently reporting this issue., per the CVE Program record.