CVE-2025-9319
7.5Lenovo · Wallpaper Client
The Lenovo Wallpaper Client contains an arbitrary code execution vulnerability due to the application failing to perform integrity checks during the download of code.
Executive summary
The Lenovo Wallpaper Client is vulnerable to arbitrary code execution, posing a critical risk to systems where the software remains installed.
Vulnerability
This vulnerability, classified as CWE-494, involves the download of code without sufficient integrity verification, which can allow an unauthenticated attacker to execute arbitrary code on the host system.
Business impact
Successful exploitation of this vulnerability allows for unauthorized code execution, which could lead to full system compromise or the installation of malicious software. With a CVSS score of 7.5, this high-severity flaw represents a significant risk to organizational integrity and data security, necessitating immediate attention.
Remediation
Immediate Action: Lenovo has officially ended support for the Wallpaper Client and recommends the immediate discontinuation and removal of the software from all systems.
Proactive Monitoring: Review system logs for unauthorized processes or unexpected network connections originating from the Lenovo Wallpaper Client directory.
Compensating Controls: Ensure that endpoint security solutions are configured to block unauthorized execution attempts and restrict the application from accessing sensitive network segments until it is successfully removed.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Because Lenovo has officially deprecated this software, there is no path for patching the underlying vulnerability. Security teams must prioritize the immediate identification and uninstallation of the Lenovo Wallpaper Client across all managed environments to eliminate this attack vector entirely.
More Lenovo CVEs
Sources
Originally found and disclosed by Lenovo thanks Wan Jie from Huazhong University of Science and Technology for reporting this issue., per the CVE Program record.