Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Lenovo App Store to version 9.0.2530.1027 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://iknow.lenovo.com.cn/detail/435004 |
|
Wed, 10 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Dec 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a local authenticated user to execute code with elevated privileges under certain conditions. | |
| First Time appeared |
Lenovo
Lenovo app Store Lenovo browser |
|
| Weaknesses | CWE-427 | |
| CPEs | cpe:2.3:a:lenovo:app_store:*:*:*:*:*:*:*:* cpe:2.3:a:lenovo:browser:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Lenovo
Lenovo app Store Lenovo browser |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2025-12-10T15:47:33.368Z
Reserved: 2025-10-21T20:00:54.017Z
Link: CVE-2025-12046
Updated: 2025-12-10T15:47:29.802Z
Status : Deferred
Published: 2025-12-10T15:15:54.907
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-12046
No data.
OpenCVE Enrichment
No data.