Improper Default Permission in Lenovo Dock Manager
CVE-2025-8421
5.2MEDIUM
What is CVE-2025-8421?
An improper default permission vulnerability has been identified in Lenovo Dock Manager. This issue can be exploited by an authenticated local user under specific installation conditions, allowing them to redirect log files with elevated privileges. It is essential for users to ensure that they are using the patched version of the software to safeguard against potential security risks and unauthorized access.
Affected Version(s)
Dock Manager 0 < 1.6.5.2
References
CVSS V4
Score:
5.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lenovo thanks Sheikh Rishad for reporting this issue.