CVE-2025-10237
PrivEsc in ThinkPad embedded controller firmware allows local memory access to privileged regions.
Is CVE-2025-10237 being exploited?
Not confirmed. CVE-2025-10237 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.08% probability of exploitation in the next 30 days.
How severe is CVE-2025-10237?
CVE-2025-10237 is rated High with a CVSS score of 8.4. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2025-10237?
Not known from our data. No patch reference has been recorded for CVE-2025-10237, which is not the same as no patch existing — a fix may have shipped without a tagged reference, or after this record was written. The vendor advisory is the only authority on whether a fix exists, and mitigations may be available regardless.
What does CVE-2025-10237 affect?
CVE-2025-10237 affects ThinkPad embedded controller firmware. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2025-10237?
Patch when available; limit physical access; monitor EC activity.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Local attacker with physical/logical access can read/write privileged EC memory, enabling further host/firmware compromise.
Patch when possible
- affected< 1.10
- affected< 1.24
- affected< 1.21
- affected< 1.15
- affected< 1.45
- affected< 1.31
- affected< 1.73
- affected< 1.36
- affected< 1.44
- affected< 1.36
- affected< 1.34
- affected< 1.27
- affected< 1.06
- affected< 1.14
- affected< 1.27
- affected< 1.40
- affected< 1.13
- affected< 1.53
- affected< 1.33
- affected< 1.47
- affected< 1.26
- affected< 1.17
- affected< UEFI BIOS V1.22/ECP V1.13
- affected<= 1.28
- affected<= 1.70
- affected< BIOS: 1.99/ ECFW: 1.58
- affected< 1.52
- affected< BIOS: 1.66 / ECFW: 1.10
- affected< 1.65/1.13
- affected<= 1.20
- affected<= 1.16
- affected<= 1.98
- affected< 1.30 / 1.15
- affected< 1.39 / 1.15
- affected< 1.18 / 1.14
- affected<= 2.01
- affected< 1.28
- affected< 1.47/1.27
- affected< 1.18
- affected< 1.49
- affected< 1.51
- affected< 1.23
- affected< 1.28
- affected< 1.15
- affected< 1.62/1.12
- affected< 1.10
- affected< 1.09
- affected< 1.11
- affected< 1.38
- affected< 1.69/1.21
- affected<= 1.98
- affected<= 1.84
- affected<= 1.68
- affected<= 1.34
- affected< 1.16
- affected< 1.12
- affected< 1.08
- affected< 1.85/1.26
- affected<= 1.36
- affected< 1.38/1.36
- affected<= 1.38
- affected<= 1.40
- affected< 1.22 / 1.15
- affected< 1.39
- affected< 1.46
- affected< 1.65
- affected< 1.36
- affected< 1.37
- affected< 1.17
- affected< 1.11
- affected< 1.09
- affected< 1.58 / 1.18
- affected< 1.52/ 1.28
- affected< 1.25
- affected< 1.22
- affected< 1.15
- affected< 1.56 / 1.26
- affected< 1.38 / 1.22
- affected< 1.34 / 1.19
- affected< 1.26
- affected<= 1.35
- affected< 1.69
- affected< 1.33 / 1.21
- affected< 1.29 / 1.11
- affected< 1.38
- affected< 1.67 / 1.56
- affected< 1.41
- affected< 1.76
- affected< 1.53
- affected< 1.38
- affected<= 1.87
- affected< 2.06 / 1.23
- affected< 1.21
- affected< 1.76
- affected< 1.37
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.