An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying an application configuration file.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-21802 An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying an application configuration file.
Fixes

Solution

Update Lenovo Vantage to version 10.2501.20.0 (or newer).


Workaround

No workaround given by the vendor.

History

Tue, 22 Jul 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Lenovo commercial Vantage
CPEs cpe:2.3:a:lenovo:commercial_vantage:*:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:vantage:*:*:*:*:*:*:*:*
Vendors & Products Lenovo commercial Vantage

Thu, 17 Jul 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Jul 2025 19:30:00 +0000

Type Values Removed Values Added
Description An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying an application configuration file.
Weaknesses CWE-88
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2025-07-17T20:12:27.411Z

Reserved: 2025-06-18T13:04:05.813Z

Link: CVE-2025-6231

cve-icon Vulnrichment

Updated: 2025-07-17T20:12:24.506Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-17T20:15:31.537

Modified: 2025-07-22T17:05:25.170

Link: CVE-2025-6231

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-21T15:17:15Z