Lenovo Dock Manager Improper Permissions: Local Authenticated Priv Escalation
CVE-2026-63425 Published on August 13, 2026
During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could allow a local authenticated user to execute arbitrary code with elevated privileges.
Vulnerability Analysis
CVE-2026-63425 can be exploited with local system access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
Products Associated with CVE-2026-63425
Want to know whenever a new CVE is published for Lenovo Dock Manager? stack.watch will email you.
Affected Versions
Lenovo Dock Manager:- Before 1.6.5.3 is affected.