Insufficient Access Control in Lenovo Dispatcher Drivers for Consumer Notebooks
CVE-2025-8061

7.3HIGH

Key Information:

Vendor

Lenovo

Vendor
CVE Published:
11 September 2025

Badges

📈 Score: 819👾 Exploit Exists🟡 Public PoC

What is CVE-2025-8061?

CVE-2025-8061 is a vulnerability associated with the Lenovo Dispatcher drivers designed for consumer notebooks. This vulnerability stems from insufficient access control mechanisms, which could potentially allow authenticated local users to execute code with elevated system privileges. Such an exploitation could present significant risks to organizations utilizing affected Lenovo devices, as malicious actors could manipulate these privileges to gain unauthorized access to critical system functions and sensitive data. It is worth noting that this issue affects specifically the Dispatcher versions 3.0 and 3.1, while version 3.2 remains secure against this vulnerability. Additionally, systems equipped with Windows 11 and utilizing the Core Isolation Memory Integrity feature are not impacted, highlighting the importance of system configurations and updates in mitigating this risk.

Potential impact of CVE-2025-8061

  1. Unauthorized System Access: The vulnerability enables authenticated local users to gain elevated privileges, allowing them to execute arbitrary code. This unauthorized access poses a major risk as it can lead to malicious activities such as data theft, system tampering, or the installation of malware.

  2. Data Breaches: With elevated privileges, attackers could access sensitive data stored on the devices, potentially leading to significant data breaches that could have legal, financial, and reputational consequences for organizations.

  3. Increased Attack Surface: The existence of this vulnerability increases the overall attack surface of affected systems within an organization, making them prime targets for other types of cyberattacks, including the installation of ransomware or other harmful software that could exploit the compromised access further.

Affected Version(s)

Dispatcher 3.0 Driver 0 < 3.1.0.41

Dispatcher 3.1 Driver 0 < 3.1.0.41

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lenovo thanks YiShun Zeng and Quarkslabs for reporting this issue.
.
CVE-2025-8061 : Insufficient Access Control in Lenovo Dispatcher Drivers for Consumer Notebooks