CVE-2026-63425: High severity Lenovo Dock Manager vulnerability
During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could allow a local authenticated user to execute arbitrary code with elevated privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Lenovo Dock Managerto a version that resolves this vulnerability.Fixed in 1.6.5.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63425?
CVE-2026-63425 has a severity rating of 7.8, categorized as high.
How do I fix CVE-2026-63425?
To address CVE-2026-63425, update to the latest version of Lenovo Dock Manager as recommended in the security advisory.
What does CVE-2026-63425 affect?
CVE-2026-63425 affects Lenovo Dock Manager, potentially allowing local authenticated users to execute arbitrary code.
What can happen if CVE-2026-63425 is exploited?
Exploitation of CVE-2026-63425 can lead to elevated privileges, enabling execution of arbitrary code by authenticated users.
Who is affected by CVE-2026-63425?
Local authenticated users of Lenovo Dock Manager are at risk from the vulnerability described in CVE-2026-63425.