PT-2025-37259 · Lenovo+1 · Lenovo Dispatcher+1
Published
2025-09-09
·
Updated
2026-04-14
·
CVE-2025-8061
CVSS v3.1
7.0
High
| AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Lenovo Dispatcher versions prior to 3.1.0.41
Description
An insufficient access control issue exists in the Lenovo Dispatcher drivers. This allows an authenticated local user to execute arbitrary code with elevated privileges. The issue involves the use of an
MSR (Model-Specific Register, used for toggling and monitoring processor-specific features) read primitive to access kernel addresses and bypass security protections. This does not affect systems where the Windows feature Core Isolation Memory Integrity is enabled.Recommendations
Update to version 3.1.0.41 or later.
Enable Windows Core Isolation Memory Integrity to mitigate the risk.
Exploit
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lenovo Dispatcher
Windows 11