cbcvebase.
CVE-2025-2501
published 2025-05-30

CVE-2025-2501: An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.

high8.5CVSS 4.0
AVLACLATNPRLUINVCHVIHVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.

Affected

6 ranges
VendorProductVersion rangeFixed in
lenovopc_manager< 5.1.110.50825.1.110.5082
lenovopcmanager< 5.1.110.50825.1.110.5082
msrcazure_stack_hub
msrcazure_stack_hub_2406
msrcazure_stack_hub_2408
msrcazure_stack_hub_2501