CVE-2025-6231

An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying an application configuration file.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:lenovo:commercial_vantage:*:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:vantage:*:*:*:*:*:*:*:*

History

22 Jul 2025, 17:05

Type Values Removed Values Added
CPE cpe:2.3:a:lenovo:commercial_vantage:*:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:vantage:*:*:*:*:*:*:*:*
First Time Lenovo commercial Vantage
Lenovo
Lenovo vantage
Summary
  • (es) Se informó de una vulnerabilidad de validación incorrecta en Lenovo Vantage que, en determinadas condiciones, podría permitir que un atacante local ejecute código con permisos elevados modificando un archivo de configuración de la aplicación.
References () https://support.lenovo.com/us/en/product_security/LEN-196648 - () https://support.lenovo.com/us/en/product_security/LEN-196648 - Vendor Advisory

17 Jul 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-17 20:15

Updated : 2025-07-22 17:05


NVD link : CVE-2025-6231

Mitre link : CVE-2025-6231

CVE.ORG link : CVE-2025-6231


JSON object : View

Products Affected

lenovo

  • commercial_vantage
  • vantage
CWE
CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')