A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drivers used by some Lenovo consumer notebooks that could allow an authenticated local user to execute code with elevated privileges. The Lenovo Dispatcher 3.2 driver is not affected. This vulnerability does not affect systems when the Windows feature Core Isolation Memory Integrity is enabled. Lenovo systems preloaded with Windows 11 have this feature enabled by default.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-200860 |
|
History
Fri, 12 Sep 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lenovo
Lenovo dispatcher Microsoft Microsoft windows Microsoft windows 11 |
|
| Vendors & Products |
Lenovo
Lenovo dispatcher Microsoft Microsoft windows Microsoft windows 11 |
Thu, 11 Sep 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Sep 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drivers used by some Lenovo consumer notebooks that could allow an authenticated local user to execute code with elevated privileges. The Lenovo Dispatcher 3.2 driver is not affected. This vulnerability does not affect systems when the Windows feature Core Isolation Memory Integrity is enabled. Lenovo systems preloaded with Windows 11 have this feature enabled by default. | |
| Weaknesses | CWE-782 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: lenovo
Published: 2025-09-11T18:34:52.421Z
Updated: 2025-09-22T15:48:36.752Z
Reserved: 2025-07-22T20:46:17.396Z
Link: CVE-2025-8061
Updated: 2025-09-11T18:54:32.798Z
Status : Awaiting Analysis
Published: 2025-09-11T19:15:35.060
Modified: 2025-09-15T15:22:38.297
Link: CVE-2025-8061
No data.