CVE-2025-8061 is a local privilege escalation vulnerability in the Lenovo Dispatcher 3.0 and 3.1 drivers used by some Lenovo consumer notebooks. The issue is described by Lenovo as a potential insufficient access control vulnerability. Available context associates the issue with the Lenovo LnvMSRIO / WinMsrDev Lenovo MSR I/O driver, version 3.1.0.35 and below, and indicates that exploitation can allow an authenticated local user to transition from user mode to kernel-level code execution. Lenovo Dispatcher 3.2 is reported as not affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This 24-file Windows x64 C/C++/MASM project is a standalone BYOVD manual kernel-driver mapper targeting CVE-2025-8061 in Lenovo's LnvMSRIO.sys. The client executable opens the WinMsrDev device, uses exposed IOCTLs for arbitrary physical-memory and MSR access, resolves ntoskrnl symbols from Microsoft PDBs, and builds virtual-to-physical mappings with NtQuerySystemInformation Superfetch PFN queries. It reads and temporarily hijacks the LSTAR syscall MSR to transition into dynamically generated ring-0 shellcode, temporarily disables SMEP/SMAP through a ROP sequence, obtains the physical address of NtAddAtom, and patches NtAddAtom with a transient jump hook. That hook is used to invoke kernel routines including ExAllocatePoolWithTag, RtlCopyMemory, and the mapped driver's DriverEntry. PE parsing and mapping code handles image allocation, section copying, relocations, imports, and security-cookie adjustment before restoring the hook and original MSRs. The driver directory contains a minimal demonstrator payload and INF; PayloadDriver.sys prints a debug message from DriverEntry. No C2, reverse shell, or exfiltration functionality is present, but the mapper provides high-impact local kernel-code execution for any replacement payload driver.
This repository is a small Windows C++ proof-of-concept for CVE-2025-8061 affecting Lenovo's LnvMSRIO.sys driver. The project contains one main source file, one helper header implementing the driver interface, Visual Studio project files, and a short README describing the impact. Structure and purpose: - Lenovo-CVE-2025-8061/Lenovo-CVE-2025-8061.cpp: main demo program. - Lenovo-CVE-2025-8061/Library.h: wrapper class around the vulnerable device and IOCTLs. - .vcxproj / .filters: Visual Studio build metadata. - README.md: brief vulnerability description and impact statement. Main exploit capabilities: - Opens the Lenovo driver device \\.\WinMsrDev from user mode. - Reads privileged MSRs, specifically IA32_LSTAR, IA32_EFER, and IA32_SYSENTER_EIP. - Reads arbitrary physical memory (demo reads 64 bytes from physical address 0x1000 and hex dumps them). - Includes helper methods for arbitrary MSR writes and arbitrary physical memory writes, even though the demo path does not invoke the write primitives. - Enumerates processes to find notepad.exe and queries its PEB address using NtQueryInformationProcess, likely as a convenience step for later kernel/user memory research. Security impact: The code demonstrates a local privilege-escalation primitive rather than a remote exploit. Because the driver exposes unrestricted IOCTLs to user mode, an unprivileged process can gain kernel-relevant read/write access. The README explicitly notes likely outcomes such as KASLR bypass via IA32_LSTAR disclosure and potential kernel code execution via IA32_LSTAR hijacking. The included code stops short of implementing a full privilege-escalation chain, so it is best characterized as an operational local exploit primitive / PoC with dangerous write capabilities already present in the helper library.
This repository is a Proof-of-Concept (PoC) exploit for CVE-2025-8061, targeting the Lenovo LnvMSRIO.sys (MSR I/O) driver on Windows. The exploit demonstrates how a local attacker with Administrator privileges can achieve arbitrary physical and kernel memory read/write by abusing vulnerable IOCTLs exposed by the driver. The exploit uses a Superfetch-based technique to translate kernel virtual addresses to physical addresses, enabling full kernel memory access even on modern Windows versions. The repository is structured as a Delphi project with the following key files: - `src/LnvMSRIOExploit.dpr`: Main entry point and orchestrator for the exploit. - `src/LnvMSRIOHandler.pas`: Handles driver loading, IOCTL communication, and memory operations. - `src/SuperfetchVtop.pas` and `src/SuperfetchTypes.pas`: Implement the Superfetch VA-to-PA translation logic. - `src/KernelMemTest.pas`: Contains test routines to verify physical and kernel memory access. - `src/SystemTypes.pas`: Defines Windows kernel types and API function pointers. The exploit requires the vulnerable driver file (`LnvMSRIO.sys`) to be present and accessible, and interacts with the device via the `\\.\WinMsrDev` device name. It manipulates the Windows registry to install the driver service. The attack vector is local privilege escalation, as the exploit must be run with Administrator rights. No network endpoints are involved. The code is a functional PoC, not weaponized, and is intended for research and authorized testing only.
This repository is a Rust-based proof-of-concept (PoC) exploit for CVE-2025-8061, a vulnerability in the Lenovo Dispatcher driver (LnvMSRIO.sys) on Windows. The exploit leverages read/write primitives exposed by the driver to overwrite the NtAddAtom function in the Windows kernel (ntoskrnl.exe) with custom shellcode. This shellcode disables SMEP, jumps to userland code to steal the SYSTEM token, and then re-enables SMEP, resulting in privilege escalation to SYSTEM. The exploit uses the Superfetch/PFN technique to translate virtual to physical addresses in user mode, which is necessary for targeting kernel memory. The code is organized into two main Rust source files: 'src/base.rs' (core exploit logic and shellcode) and 'src/main.rs' (entry point). The exploit requires administrative privileges and is tested on Windows 10 (22H2) and Windows 11 (25H2). Key fingerprintable endpoints include the device path '\\.\WinMsrDev' and the kernel image path 'C:\Windows\System32\ntoskrnl.exe'.
This repository is a functional local privilege escalation exploit for CVE-2025-8061, targeting the Lenovo LnvMSRIO.sys driver (version 3.1.0.36) on Windows 11 24H2 (build 26100.1.amd64fre.ge_release.240331-1435). The exploit is implemented in C and x64 assembly, with the main logic in 'lenovopoc/lenovopoc.cpp' and supporting stack preparation in 'lenovopoc/PrepareStack.asm'. The exploit interacts directly with the vulnerable driver via the device interface '\\.\WinMsrDev', using custom IOCTLs to read and write Model Specific Registers (MSRs). It disables SMEP, locates kernel gadgets, and executes custom shellcode that performs token stealing to elevate the current process to SYSTEM privileges. Upon success, it spawns a SYSTEM-level command shell (cmd.exe). The exploit is operational but requires the target system to match specific Windows and driver versions, and for certain security features (KVAShadowing, Core Isolation) to be disabled. The repository includes build files for Visual Studio and detailed exploitation notes in the README. No network endpoints are involved; the attack vector is local, requiring code execution on the target machine.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
36 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.