CVE-2025-6232: Lenovo Commercial Vantage

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying specific registry locations.

Affected products

  • Lenovo Commercial Vantage: before 20.2506.39.0 (fixed in 20.2506.39.0)
  • Lenovo Vantage: before 10.2501.20.0 (fixed in 10.2501.20.0)

Published 2025-07-17. Last modified 2026-06-17.