A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drivers used by some Lenovo consumer notebooks that could allow an authenticated local user to execute code with elevated privileges. The Lenovo Dispatcher 3.2 driver is not affected. This vulnerability does not affect systems when the Windows feature Core Isolation Memory Integrity is enabled. Lenovo systems preloaded with Windows 11 have this feature enabled by default.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://support.lenovo.com/us/en/product_security/LEN-200860 |
![]() ![]() |
History
Fri, 12 Sep 2025 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lenovo
Lenovo dispatcher Microsoft Microsoft windows Microsoft windows 11 |
|
Vendors & Products |
Lenovo
Lenovo dispatcher Microsoft Microsoft windows Microsoft windows 11 |
Thu, 11 Sep 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 11 Sep 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drivers used by some Lenovo consumer notebooks that could allow an authenticated local user to execute code with elevated privileges. The Lenovo Dispatcher 3.2 driver is not affected. This vulnerability does not affect systems when the Windows feature Core Isolation Memory Integrity is enabled. Lenovo systems preloaded with Windows 11 have this feature enabled by default. | |
Weaknesses | CWE-782 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: lenovo
Published: 2025-09-11T18:34:52.421Z
Updated: 2025-09-11T18:54:41.582Z
Reserved: 2025-07-22T20:46:17.396Z
Link: CVE-2025-8061

Updated: 2025-09-11T18:54:32.798Z

Status : Received
Published: 2025-09-11T19:15:35.060
Modified: 2025-09-11T19:15:35.060
Link: CVE-2025-8061

No data.