CVE-2025-2503

A

n improper permission handling vulnerability was reported in Lenovo PC Manager that could allow a local attacker to perform arbitrary file deletions as an elevated user.

References
Link Resource
https://iknow.lenovo.com.cn/detail/428586 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:lenovo:pcmanager:*:*:*:*:*:*:*:*

History

02 Feb 2026, 15:31

Type Values Removed Values Added
CPE cpe:2.3:a:lenovo:pcmanager:*:*:*:*:*:*:*:*
References () https://iknow.lenovo.com.cn/detail/428586 - () https://iknow.lenovo.com.cn/detail/428586 - Vendor Advisory
First Time Lenovo pcmanager
Lenovo

21 Aug 2025, 16:15

Type Values Removed Values Added
CWE CWE-280 CWE-732
Summary
  • (es) Se informó de una vulnerabilidad de manejo inadecuado de permisos en Lenovo PC Manager que podría permitir que un atacante local realice eliminaciones arbitrarias de archivos como un usuario elevado.

30 May 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-30 20:15

Updated : 2026-02-02 15:31


NVD link : CVE-2025-2503

Mitre link : CVE-2025-2503

CVE.ORG link : CVE-2025-2503


JSON object : View

Products Affected
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource