A buffer overflow vulnerability was reported in the Lenovo Protection Driver, prior to version 5.1.1110.4231, used in Lenovo PC Manager, Lenovo Browser, and Lenovo App Store could allow a local attacker with elevated privileges to execute arbitrary code.
Fixes

Solution

Update Lenovo PC Manager to version 5.1.110.5082 or later.


Workaround

No workaround given by the vendor.

References
History

Fri, 18 Jul 2025 08:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Jul 2025 19:30:00 +0000

Type Values Removed Values Added
Description A buffer overflow vulnerability was reported in the Lenovo Protection Driver, prior to version 5.1.1110.4231, used in Lenovo PC Manager, Lenovo Browser, and Lenovo App Store could allow a local attacker with elevated privileges to execute arbitrary code.
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2025-07-17T20:05:36.540Z

Reserved: 2025-05-13T15:36:36.096Z

Link: CVE-2025-4657

cve-icon Vulnrichment

Updated: 2025-07-17T20:05:32.041Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-17T20:15:30.313

Modified: 2025-07-17T21:15:50.197

Link: CVE-2025-4657

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.