CVE-2025-6231

An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying an application configuration file.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:lenovo:commercial_vantage:*:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:vantage:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-07-17 20:15

Updated : 2025-07-22 17:05


NVD link : CVE-2025-6231

Mitre link : CVE-2025-6231

CVE.ORG link : CVE-2025-6231


JSON object : View

Products Affected

lenovo

  • commercial_vantage
  • vantage
CWE
CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')