CVE-2025-8061

HIGH

Lenovo Dispatcher <3.1 - Privilege Escalation

Title source: llm

Description

A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drivers used by some Lenovo consumer notebooks that could allow an authenticated local user to execute code with elevated privileges. The Lenovo Dispatcher 3.2 driver is not affected. This vulnerability does not affect systems when the Windows feature Core Isolation Memory Integrity is enabled. Lenovo systems preloaded with Windows 11 have this feature enabled by default.

Exploits (4)

github WORKING POC 118 stars
by symeonp · c++poc
https://github.com/symeonp/Lenovo-CVE-2025-8061
nomisec WRITEUP 7 stars
by spawn451 · poc
https://github.com/spawn451/CVE-2025-8061-Exploit
nomisec WORKING POC 3 stars
by segura2010 · poc
https://github.com/segura2010/lenovo-dispatcher-poc
github WORKING POC 2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2025/CVE-2025-8061

Scores

CVSS v3 7.0
EPSS 0.0001
EPSS Percentile 0.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-782
Status draft

Timeline

Published Sep 11, 2025
Tracked Since Feb 18, 2026