Buffer Overflow Vulnerability in Lenovo Protection Driver Affecting Lenovo Products
CVE-2025-4657

8.4HIGH

Key Information:

Vendor

Lenovo

Vendor
CVE Published:
17 July 2025

What is CVE-2025-4657?

A buffer overflow vulnerability exists in the Lenovo Protection Driver prior to version 5.1.1110.4231, utilized across several Lenovo platforms including Lenovo PC Manager, Lenovo Browser, and Lenovo App Store. This flaw could allow a local attacker with elevated privileges to execute arbitrary code, potentially leading to unauthorized access or impact on system integrity.

Affected Version(s)

App Store 0 < 9.0.2230.0617

Browser 0 < 9.0.6.5061

PC Manager 0 < 5.1.110.5082

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lenovo thanks Gareth Evans of Kryc for reporting this issue.
.
CVE-2025-4657 : Buffer Overflow Vulnerability in Lenovo Protection Driver Affecting Lenovo Products