Home

Description

An improper default permission vulnerability was reported in Lenovo Dock Manager that, under certain conditions during installation, could allow an authenticated local user to redirect log files with elevated privileges.

PUBLISHED Reserved 2025-07-31 | Published 2025-11-12 | Updated 2025-11-12 | Assigner lenovo




MEDIUM: 5.2CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

MEDIUM: 6.6CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H

Problem types

CWE-276: Incorrect Default Permissions

Product status

Default status
unaffected

Any version before 1.6.5.2
affected

Credits

Lenovo thanks Sheikh Rishad for reporting this issue. finder

References

support.lenovo.com/us/en/product_security/LEN-198729

cve.org (CVE-2025-8421)

nvd.nist.gov (CVE-2025-8421)

Download JSON