CVE-2025-8061

A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drivers used by some Lenovo...

Basic Information

CVE State
PUBLISHED
Reserved Date
July 22, 2025
Published Date
September 11, 2025
Last Updated
September 22, 2025
Vendor
Lenovo
Product
Dispatcher 3.0 Driver, Dispatcher 3.1 Driver
Description
A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drivers used by some Lenovo consumer notebooks that could allow an authenticated local user to execute code with elevated privileges. The Lenovo Dispatcher 3.2 driver is not affected. This vulnerability does not affect systems when the Windows feature Core Isolation Memory Integrity is enabled. Lenovo systems preloaded with Windows 11 have this feature enabled by default.

CVSS Scores

CVSS v4.0

7.3 - HIGH

Vector: CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS v3.1

7.0 - HIGH

Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

SSVC Information

Exploitation
none
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2025-11-17 15:00:08 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
The Shadowserver (via CIRCL) 2025-11-17 15:00:08 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel