Improper Default Permission in Lenovo Dock Manager
CVE-2025-8421

5.2MEDIUM

Key Information:

Vendor

Lenovo

Vendor
CVE Published:
12 November 2025

What is CVE-2025-8421?

An improper default permission vulnerability has been identified in Lenovo Dock Manager. This issue can be exploited by an authenticated local user under specific installation conditions, allowing them to redirect log files with elevated privileges. It is essential for users to ensure that they are using the patched version of the software to safeguard against potential security risks and unauthorized access.

Affected Version(s)

Dock Manager 0 < 1.6.5.2

References

CVSS V4

Score:
5.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lenovo thanks Sheikh Rishad for reporting this issue.
.
CVE-2025-8421 : Improper Default Permission in Lenovo Dock Manager