← back
CVE-2025-8421

CVE-2025-8421

CVSS 5.2 MEDIUMEPSS 0.1%CWE-276
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.2EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
12 Nov 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An improper default permission vulnerability was reported in Lenovo Dock Manager that, under certain conditions during installation, could allow an authenticated local user to redirect log files with elevated privileges.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Lenovo · Dock Manager

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →