CVE-2025-8486
7.8Lenovo · PC Manager
A local privilege escalation vulnerability in Lenovo PC Manager allows an authenticated user to execute code with elevated privileges.
Executive summary
A vulnerability in Lenovo PC Manager allows a local authenticated user to gain elevated privileges, potentially leading to full system compromise.
Vulnerability
This is a privilege escalation vulnerability categorized as CWE-250 (Execution with Unnecessary Privileges). It allows a local user, who has already gained standard authentication to the system, to elevate their access to higher privilege levels by exploiting the PC Manager application.
Business impact
The ability for a standard user to escalate privileges represents a significant risk to the integrity and security of the host system. With elevated privileges, an attacker could bypass security controls, modify system files, or install persistent malicious software. Given the CVSS score of 7.8, this vulnerability is classified as High severity, necessitating prompt remediation to prevent unauthorized administrative control.
Remediation
Immediate Action: Update Lenovo PC Manager to version 5.1.140.9262 or later immediately.
Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected administrative tasks performed by standard user accounts.
Compensating Controls: Ensure that the principle of least privilege is strictly enforced across the environment to limit the number of users who can interact with sensitive management applications.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The risk associated with this vulnerability is significant for any environment where Lenovo PC Manager is deployed. Security teams should prioritize updating all affected installations to the patched version, 5.1.140.9262, to eliminate the privilege escalation path. Failure to patch allows any compromised standard account on a local machine to potentially achieve full administrative control.
More Lenovo CVEs
Sources
Originally found and disclosed by Lenovo thanks CNVD for reporting CVE-2025-8486., per the CVE Program record.