CVE-2025-12046: High severity Lenovo Lenovo App Store vulnerability
A DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a local authenticated user to execute code with elevated privileges under certain conditions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Lenovo App Storeto a version that resolves this vulnerability.Fixed in 9.0.2530.1027 - Upgrade
Upgrade
Lenovo Browserto a version that resolves this vulnerability.Fixed in 9.0.6.11071
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12046?
The severity of CVE-2025-12046 is considered to be high due to its potential for allowing local authenticated users to execute code with elevated privileges.
How do I fix CVE-2025-12046?
To fix CVE-2025-12046, ensure that you update the Lenovo App Store and Lenovo Browser applications to the latest versions provided by Lenovo.
Who is affected by CVE-2025-12046?
CVE-2025-12046 affects users of the Lenovo App Store and Lenovo Browser applications, particularly local authenticated users.
What is DLL hijacking in the context of CVE-2025-12046?
DLL hijacking refers to a type of vulnerability where an attacker can exploit the incorrect loading of dynamic link libraries to execute malicious code.
Can CVE-2025-12046 be exploited remotely?
No, CVE-2025-12046 requires local access to exploit, as it involves executing code with elevated privileges by an authenticated user.