CVE-2025-9201
7.8Lenovo · Lenovo Browser
Lenovo Browser is vulnerable to a DLL hijacking flaw, allowing local users with low privileges to execute arbitrary code with elevated permissions.
Executive summary
A DLL hijacking vulnerability in Lenovo Browser could allow a local attacker to execute code with elevated privileges, posing a significant risk to system integrity.
Vulnerability
This vulnerability is an uncontrolled search path element (CWE-427) that occurs due to improper handling of dynamic link libraries. An authenticated local user can trigger this flaw to execute code with escalated privileges.
Business impact
The ability for a local user to execute code with elevated privileges represents a complete compromise of the affected host system. Given the CVSS score of 7.8, this high-severity vulnerability could facilitate unauthorized system access, data theft, or the installation of persistent malicious software.
Remediation
Immediate Action: Update Lenovo Browser to version 9.0.6.8111 or later as specified by the vendor security advisory.
Proactive Monitoring: Review system logs for unauthorized file modifications or suspicious process execution patterns originating from the browser directory.
Compensating Controls: Ensure strict local access controls are enforced and restrict the ability of non-privileged users to write files to application installation directories.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The risk of local privilege escalation requires immediate attention to prevent unauthorized system control. Administrators must prioritize updating all instances of Lenovo Browser to the patched version 9.0.6.8111 to eliminate the potential for DLL hijacking.