CVE-2025-0886

HIGH

Elliptic Labs Virtual Lock Sensor - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-0886. PoCs published by JNDataRT.

AI-analyzed exploit summary This is a functional local privilege escalation (LPE) exploit for CVE-2025-0886 targeting Elliptic Virtual Lock Sensor version 3.1.60531.2 on Windows. It manipulates registry permissions and forces a reinstall to execute a payload as SYSTEM via the edgeupdate service.

Description

An incorrect permissions vulnerability was reported in Elliptic Labs Virtual Lock Sensor that could allow a local, authenticated user to escalate privileges.

Exploits (1)

nomisec WORKING POC 1 stars
by JNDataRT · poc
https://github.com/JNDataRT/VirtualLockSensorLPE

This is a functional local privilege escalation (LPE) exploit for CVE-2025-0886 targeting Elliptic Virtual Lock Sensor version 3.1.60531.2 on Windows. It manipulates registry permissions and forces a reinstall to execute a payload as SYSTEM via the edgeupdate service.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Elliptic Virtual Lock Sensor version 3.1.60531.2
Auth required
Prerequisites: Elliptic Virtual Lock Sensor version 3.1.60531.2 installed · Regular user access on Windows
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v3 7.8
EPSS 0.0016
EPSS Percentile 5.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-276
Status published
Products (33)
Lenovo/Elliptic Human Presence Detection Device Driver for T14 Gen 4 (Type 21K3, 21K4) < 1000.100.108.1893
Lenovo/Elliptic Human Presence Detection Device Driver for T14 Gen 5 (Type 21ML, 21MM) < 1000.100.108.801
Lenovo/Elliptic Human Presence Detection Device Driver for T14s Gen 5 (Type 21LS, 21LT) < 1000.100.108.801
Lenovo/Elliptic Human Presence Detection Device Driver for T16 Gen 2 (Type 21K7 21K8) < 1000.100.106.2391
Lenovo/Elliptic Human Presence Detection Device Driver for T16 Gen 3 (Type 21MN, 21MQ) < 1000.100.108.801
Lenovo/Elliptic Human Presence Detection Device Driver for ThinkPad P14s Gen 4 (Type 21K5, 21K6) < 1000.100.108.1893
Lenovo/Elliptic Human Presence Detection Device Driver for ThinkPad P14s Gen 5 (Type 21ME, 21MF) < 1000.100.108.6136
Lenovo/Elliptic Human Presence detection Device Driver for ThinkPad P16 Gen 2 (Type 21FA, 21FB) < 1000.100.108.774
Lenovo/Elliptic Human Presence Detection Device Driver for ThinkPad P16s Gen 2 (Type 21K9, 21KA) < 1000.100.106.2391
Lenovo/Elliptic Human Presence Detection Device Driver for ThinkPad P16v Gen 1 (Type 21FC, 21FD) < 1000.100.108.900
... and 23 more
Published Jul 17, 2025
Tracked Since Feb 18, 2026