CVE-2025-4657: Lenovo App Store

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

A buffer overflow vulnerability was reported in the Lenovo Protection Driver, prior to version 5.1.1110.4231, used in Lenovo PC Manager, Lenovo Browser, and Lenovo App Store could allow a local attacker with elevated privileges to execute arbitrary code.

Affected products

  • Lenovo App Store: before 9.0.2230.0617 (fixed in 9.0.2230.0617)
  • Lenovo Browser: before 9.0.6.5061 (fixed in 9.0.6.5061)
  • Lenovo Pc Manager: before 5.1.110.5082 (fixed in 5.1.110.5082)

Published 2025-07-17. Last modified 2026-06-17.