Junglewise Threat Intelligence

CVE-2025-10237: Lenovo ThinkPad arbitrary memory access in embedded controller firmware

CVE-2025-10237 · Severity: medium · CVSS 6.7 · Published 2026-06-10

Vendors: Lenovo.

Executive brief

A security vulnerability has been identified in the firmware of certain Lenovo ThinkPad laptops. This flaw could allow a user who already has administrative access to the computer to read or modify sensitive areas of the system's memory. Such access could potentially be used to bypass security protections or cause system instability.

Technical details

This vulnerability exists in the embedded controller (EC) firmware of certain Lenovo ThinkPad models. The flaw allows a local attacker with high privileges (administrative/root) to perform arbitrary memory read and write operations within privileged memory regions. While the advisory references CWE-327 (Use of a Broken or Risky Cryptographic Algorithm), the primary impact is an escalation of privilege or bypass of firmware-level protections via direct memory access. Exploitation requires local access and existing administrative rights on the host operating system. Users are advised to refer to Lenovo advisory LEN-218282 for specific firmware updates.

Affected products

  • Lenovo ThinkPad Embedded Controller Firmware

Timeline

  • 2026-06-10: disclosed
  • 2026-06-10: advisory: Lenovo published security advisory LEN-218282

References