CVE-2025-10495

HIGH

Lenovo Client Apps - RCE

Title source: llm
STIX 2.1

Description

A potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zone client applications that, under certain conditions, could allow an attacker on the same logical network to execute arbitrary code.

Scores

CVSS v3 7.5
EPSS 0.0003
EPSS Percentile 8.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-295
Status published
Products (4)
Lenovo/App Store < 9.0.2530.1027
Lenovo/Browser < 9.0.6.9111
Lenovo/Legion Zone < 2.0.21
Lenovo/PC Manager < 5.1.140.9262
Published Nov 12, 2025
Tracked Since Feb 18, 2026