Vulnerabilidades en Lenovo

394 resultados
Análisis Vexday

Com 369 CVEs catalogadas, o portfólio de vulnerabilidades da Lenovo apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de exploração em curso. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), o que sugere atenção recorrente à sanitização de dados em componentes de firmware e software proprietário. A CVE mais perigosa identificada atualmente é CVE-2022-3699, com score EPSS de 0,0428 — o maior valor observado no conjunto —, indicando probabilidade de exploração ainda relativamente baixa, mas suficiente para justificar priorização em ambientes corporativos que dependem de hardware Lenovo. As 13 vulnerabilidades surgidas nos últimos 90 dias e a presença de 4 falhas críticas reforçam a necessidade de ciclos regulares de atualização de firmware e drivers.

CVE-2025-13152HIGHA potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that could allow a local auEPSS 0.1%CVE-2026-6511MEDIUMDuring an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for WindowsEPSS 0.1%CVE-2026-63424HIGHDuring an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authenticEPSS 0.1%CVE-2025-13455HIGHA vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass ThinkPlus device authEPSS 0.1%CVE-2026-0940HIGHA potential improper initialization vulnerability was reported in the BIOS of some ThinkPads that could allow a local privileged user to modEPSS 0.1%CVE-2026-2368HIGHAn improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of interceptinEPSS 0.1%CVE-2026-16791LOWPredictable Temporary File Symlink Vulnerability in Lenovo XClarity Essentials OneCLIEPSS 0.1%CVE-2025-2503MEDIUMAn improper permission handling vulnerability was reported in Lenovo PC Manager that could allow a local attacker to perform arbitrary file EPSS 0.1%CVE-2024-10254MEDIUMA potential buffer overflow vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attackerEPSS 0.1%CVE-2026-1636MEDIUMA potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticaEPSS 0.1%CVE-2026-9046HIGHA potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusEPSS 0.1%CVE-2024-10253MEDIUMA potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to causeEPSS 0.1%CVE-2025-8485HIGHAn improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to execute code with elevEPSS 0.1%CVE-2026-2640MEDIUMDuring an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a local authenticatedEPSS 0.1%CVE-2025-10238HIGHDuring an internal security assessment, a potential out-of-bounds write vulnerability was discovered in the BIOS of some ThinkPad products cEPSS 0.1%CVE-2025-8098HIGHAn improper permission vulnerability was reported in Lenovo PC Manager that could allow a local attacker to escalate privileges.EPSS 0.1%CVE-2025-13155HIGHAn improper permissions vulnerability was reported in Lenovo Baiying Client that could allow a local authenticated user to execute code withEPSS 0.1%CVE-2022-3701HIGH A privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin version 2.0.0.212 and earlier that could allow aEPSS 0.1%CVE-2025-9548MEDIUMA potential null pointer dereference vulnerability was reported in the Lenovo Power Management Driver that could allow a local authenticatedEPSS 0.1%CVE-2022-3702MEDIUM A denial of service vulnerability was reported in Lenovo Vantage HardwareScan Plugin version 1.3.0.5 and earlier that could allow a local aEPSS 0.1%