CVE-2025-9201

7.8

Lenovo · Lenovo Browser

Lenovo Browser is vulnerable to a DLL hijacking flaw, allowing local users with low privileges to execute arbitrary code with elevated permissions.

Executive summary

A DLL hijacking vulnerability in Lenovo Browser could allow a local attacker to execute code with elevated privileges, posing a significant risk to system integrity.

Vulnerability

This vulnerability is an uncontrolled search path element (CWE-427) that occurs due to improper handling of dynamic link libraries. An authenticated local user can trigger this flaw to execute code with escalated privileges.

Business impact

The ability for a local user to execute code with elevated privileges represents a complete compromise of the affected host system. Given the CVSS score of 7.8, this high-severity vulnerability could facilitate unauthorized system access, data theft, or the installation of persistent malicious software.

Remediation

Immediate Action: Update Lenovo Browser to version 9.0.6.8111 or later as specified by the vendor security advisory.

Proactive Monitoring: Review system logs for unauthorized file modifications or suspicious process execution patterns originating from the browser directory.

Compensating Controls: Ensure strict local access controls are enforced and restrict the ability of non-privileged users to write files to application installation directories.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The risk of local privilege escalation requires immediate attention to prevent unauthorized system control. Administrators must prioritize updating all instances of Lenovo Browser to the patched version 9.0.6.8111 to eliminate the potential for DLL hijacking.

More Lenovo CVEs

Sources