An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying specific registry locations.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-21801 An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying specific registry locations.
Fixes

Solution

Update Lenovo Vantage to version 10.2501.20.0 (or newer).


Workaround

No workaround given by the vendor.

History

Tue, 22 Jul 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Lenovo commercial Vantage
CPEs cpe:2.3:a:lenovo:commercial_vantage:*:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:vantage:*:*:*:*:*:*:*:*
Vendors & Products Lenovo commercial Vantage

Thu, 17 Jul 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Jul 2025 19:30:00 +0000

Type Values Removed Values Added
Description An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying specific registry locations.
Weaknesses CWE-88
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2025-07-17T20:12:52.204Z

Reserved: 2025-06-18T13:04:06.567Z

Link: CVE-2025-6232

cve-icon Vulnrichment

Updated: 2025-07-17T20:12:48.701Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-17T20:15:31.700

Modified: 2025-07-22T17:05:42.733

Link: CVE-2025-6232

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-21T15:17:14Z