CVE-2025-4657: Lenovo App Store
Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.
A buffer overflow vulnerability was reported in the Lenovo Protection Driver, prior to version 5.1.1110.4231, used in Lenovo PC Manager, Lenovo Browser, and Lenovo App Store could allow a local attacker with elevated privileges to execute arbitrary code.
Affected products
- Lenovo App Store: before 9.0.2230.0617 (fixed in 9.0.2230.0617)
- Lenovo Browser: before 9.0.6.5061 (fixed in 9.0.6.5061)
- Lenovo Pc Manager: before 5.1.110.5082 (fixed in 5.1.110.5082)
Published 2025-07-17. Last modified 2026-06-17.