Lenovo Vantage Vulnerabilities Allow Attackers to Escalate Privileges as SYSTEM User

A trio of newly disclosed CVE-2025-6230, CVE-2025-6231 and CVE-2025-6232 underscores how a single trusted OEM utility can become a springboard for full machine compromise. Lenovo Vantage, shipped by default on most modern ThinkPad and ThinkBook laptops, runs a core service asNT AUTHORITY\SYSTEMand dynamically loads C# plug-ins to expose update, hardware-control and telemetry features. Because these add-ins are expected to talk to the privileged service through a proprietary JSON-over-RPC protoco...

Save to Folder

Choose a folder to save this article: