A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drivers used by some Lenovo consumer notebooks that could allow an authenticated local user to execute code with elevated privileges. The Lenovo Dispatcher 3.2 driver is not affected. This vulnerability does not affect systems when the Windows feature Core Isolation Memory Integrity is enabled. Lenovo systems preloaded with Windows 11 have this feature enabled by default.
Fixes

Solution

Update to the version (or newer) indicated for your model in the Product Impact section in the advisory:  https://support.lenovo.com/us/en/product_security/LEN-200860


Workaround

No workaround given by the vendor.

History

Thu, 11 Sep 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 11 Sep 2025 18:45:00 +0000

Type Values Removed Values Added
Description A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drivers used by some Lenovo consumer notebooks that could allow an authenticated local user to execute code with elevated privileges. The Lenovo Dispatcher 3.2 driver is not affected. This vulnerability does not affect systems when the Windows feature Core Isolation Memory Integrity is enabled. Lenovo systems preloaded with Windows 11 have this feature enabled by default.
Weaknesses CWE-782
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2025-09-11T18:54:41.582Z

Reserved: 2025-07-22T20:46:17.396Z

Link: CVE-2025-8061

cve-icon Vulnrichment

Updated: 2025-09-11T18:54:32.798Z

cve-icon NVD

Status : Received

Published: 2025-09-11T19:15:35.060

Modified: 2025-09-11T19:15:35.060

Link: CVE-2025-8061

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.