Junglewise Threat Intelligence

CVE-2026-2640: Lenovo PC Manager privilege escalation via process termination

CVE-2026-2640 · Severity: medium · CVSS 5.5 · Published 2026-03-11

Vendors: Lenovo.

Executive brief

Lenovo PC Manager is a system maintenance utility installed on many Lenovo computers. A vulnerability allows an authenticated local user to terminate privileged system processes, potentially disrupting critical operations or enabling further system compromise. This could affect business continuity and system stability on affected Lenovo PCs.

Technical details

The vulnerability is a privilege escalation issue in Lenovo PC Manager that permits a local authenticated user to terminate high-privileged processes. The attack vector is local and requires prior authentication/access to the affected system. An attacker can abuse this capability to kill critical system processes, causing denial of service or creating conditions for further exploitation. The vulnerability was discovered during an internal security assessment and has not been observed in active exploitation in the wild as of the publication date.

Affected products

  • Lenovo PC Manager

Timeline

  • 2026-03-11: disclosed

References