← Vulnerability feed

Vulnerability record · CVE-2025-10581 · published 15 October 2025

CVE-2025-10581: Lenovo pcmanager uncontrolled search path element vulnerability

Lenovo · Pcmanager

A potential DLL hijacking vulnerability was discovered in the Lenovo PC Manager during an internal security assessment that could allow a local authenticated user to execute code with elevated privileges.

8.5 CVSS 4.0 High EPSS 0.16% · top 96.1% CWE-427 · Uncontrolled search path element
8.5CVSS 4.0 base score
0.16%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

A potential DLL hijacking vulnerability was discovered in the Lenovo PC Manager during an internal security assessment that could allow a local authenticated user to execute code with elevated privileges.

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-10581 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-1513Lenovo pcmanager os command injection vulnerabilityA potential vulnerability was reported in Lenovo PCManager prior to version 5.0.10.4191 that may allow code execution when visiting a specially craft…EPSS 0.56%8.5CVE-2025-8486Lenovo pcmanager execution with unnecessary privileges vulnerabilityA potential vulnerability was reported in PC Manager that could allow a local authenticated user to execute code with elevated privileges.EPSS 0.16%8.5CVE-2025-8098Lenovo pcmanager incorrect default permissions vulnerabilityAn improper permission vulnerability was reported in Lenovo PC Manager that could allow a local attacker to escalate privileges.EPSS 0.12%8.5CVE-2025-2501Lenovo pcmanager untrusted search path vulnerabilityAn untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.EPSS 0.18%8.5CVE-2025-2502Lenovo pcmanager incorrect default permissions vulnerabilityAn improper default permissions vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.EPSS 0.20%7.8CVE-2019-6197Lenovo pcmanager improper authentication vulnerabilityA vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.EPSS 0.14%7.8CVE-2019-6198Lenovo pcmanager improper authentication vulnerabilityA vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.EPSS 0.14%7.8CVE-2022-0192Lenovo pcmanager uncontrolled search path element vulnerabilityA DLL search path vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow privilege escalation.EPSS 0.25%

Source: NIST National Vulnerability Database (record CVE-2025-10581), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.