CVE-2025-8485

7.3

Lenovo · App Store

An improper permissions vulnerability in the Lenovo App Store allows local authenticated users to execute code with elevated privileges during application installation.

Executive summary

A local privilege escalation vulnerability in the Lenovo App Store could allow authenticated users to execute malicious code with elevated system privileges.

Vulnerability

This flaw stems from incorrect default permissions (CWE-276) within the Lenovo App Store, which fails to properly restrict access during the application installation process. The vulnerability requires the attacker to be an authenticated local user who can then leverage this flaw to gain elevated execution rights.

Business impact

Successful exploitation of this vulnerability enables a local user to bypass standard security controls and execute arbitrary code with elevated privileges. Given the CVSS score of 7.3, this represents a high risk to organizational security, as it could facilitate unauthorized system modification, data theft, or the installation of persistent malicious software on compromised workstations.

Remediation

Immediate Action: Update the Lenovo App Store client to version 9.0.2530.1027 or later immediately to resolve the insecure permission handling.

Proactive Monitoring: Review system access logs for unusual installation activity or unauthorized process spawning originating from the Lenovo App Store service.

Compensating Controls: Restrict local user permissions where possible to limit the ability of non-administrative users to execute unauthorized software or modify system-level installation directories.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability presents a significant risk to the integrity of endpoints running the Lenovo App Store. Administrators should prioritize the deployment of the provided update across all managed Lenovo devices to close the privilege escalation vector and prevent potential local exploitation.

More Lenovo CVEs

Sources

Originally found and disclosed by Lenovo thanks Wanjie from Huazhong University of Science and Technology for reporting this issue., per the CVE Program record.