CVE-2025-2501
published 2025-05-30CVE-2025-2501: An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.15%
5.1th percentile
An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lenovo | pc_manager | < 5.1.110.5082 | 5.1.110.5082 |
| lenovo | pcmanager | < 5.1.110.5082 | 5.1.110.5082 |
| msrc | azure_stack_hub | — | — |
| msrc | azure_stack_hub_2406 | — | — |
| msrc | azure_stack_hub_2408 | — | — |
| msrc | azure_stack_hub_2501 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.5HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7m65-wj64-957x: An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges
ghsa_unreviewed·2025-05-30
CVE-2025-2501 [HIGH] CWE-426 GHSA-7m65-wj64-957x: An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges
An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.
Microsoft
Azure Stack Hub Information Disclosure Vulnerability
vendor_msrc·2025-08-12·CVSS 7.5
CVE-2025-53793 [HIGH] CWE-287 Azure Stack Hub Information Disclosure Vulnerability
Azure Stack Hub Information Disclosure Vulnerability
Description: Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network.
FAQ: What type of information could be disclosed by this vulnerability?
System internal configuration could be disclosed by this vulnerability.
FAQ: What should users do to protect themselves?
Users can follow the instructions in the release notes to update the Azure Stack Hub environment to latest version 1.2501.1.47.
FAQ: There are multiple update packages available for some of the affected software. Do I need to install all the updates listed in the Security Updates table for the software?
Yes. Customers should apply all updates offered for the software installed on their systems. If multiple updates apply, t
Microsoft
Azure Stack Hub Information Disclosure Vulnerability
vendor_msrc·2025-08-12·CVSS 4.4
CVE-2025-53765 [MEDIUM] CWE-359 Azure Stack Hub Information Disclosure Vulnerability
Azure Stack Hub Information Disclosure Vulnerability
Description: Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
This vulnerability could disclose administrator account passwords in the logs.
Azure Stack: Azure Stack
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Information Disclosure
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely
Remediation: Release Notes
Reference: https://aka.ms/appsvcupdate25R1installer
Reference: https://learn.microsoft.com/en-us/azure-stack/operator/app-service-release-notes-2025r1?view=azs-2501&tabs=EntraID
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-05-30
Published