Incorrect Default Permissions
CVE-2025-8421
Summary
An improper default permission vulnerability was reported in Lenovo Dock Manager that, under certain conditions during installation, could allow an authenticated local user to redirect log files with elevated privileges.
- LOW
- LOCAL
- HIGH
- UNCHANGED
- REQUIRED
- LOW
- NONE
- HIGH
CWE-276 - Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
References
Advisory Timeline
- Published