Skip to content
Threat Feed
low advisory

Denial of Service in Lenovo Power Management Driver (CVE-2025-9548)

An authenticated local user can trigger a system-wide denial of service by exploiting a null pointer dereference vulnerability in the Lenovo Power Management Driver, pmdrvs.sys.

CVE search metadata

CVE search record: CVE-2025-9548. Severity: medium. CVSS: 5.5. EPSS: 0.12%. KEV: no. Product: Power Management Driver (< 1.69.70.0). Brief: Denial of Service in Lenovo Power Management Driver (CVE-2025-9548). Brief link: https://feed.craftedsignal.io/briefs/2026-10-lenovo-pmdrvs-dos/

CVE-2025-9548 is a null pointer dereference vulnerability residing in the Lenovo Power Management Driver (pmdrvs.sys) affecting versions prior to 1.69.70.0. The vulnerability allows an authenticated local user with sufficient privileges to send a crafted IOCTL request to the driver interface, triggering an unhandled exception that results in a system crash (Blue Screen of Death). The researcher, Sam Dalgleish, publicly released a proof-of-concept (PoC) tool on October 10, 2026, which demonstrates the ability to invoke the crash by sending IOCTL 0x802B2243 to the device object '\.\pmdrvs'. While the vulnerability is limited to a local denial of service and does not inherently provide privilege escalation or arbitrary code execution, the availability of functional exploit code increases the risk for unpatched enterprise workstations and laptops.

Impact

Successful exploitation results in an immediate system-wide denial of service, forcing a reboot and potential data loss for any user with active sessions. The vulnerability affects a broad range of Lenovo hardware utilizing the affected Power Management Driver versions.

Recommendation

  1. Patch all Lenovo systems immediately by upgrading the Power Management Driver to version 1.69.70.0 or later.
  2. Audit high-availability or critical workstations for the presence of pmdrvs.sys versions earlier than 1.69.70.0.
  3. Deploy detection logic to identify the execution of the identified PoC or similar attempts to interface with the vulnerable driver IOCTL interface.

Immediate actions

Patch Lenovo Power Management Driver to 1.69.70.0

IT Operations 72h

Deploy Sigma detection rule for PoC usage

Detection Engineering 24h

Mitigations

Upgrade Power Management Driver to 1.69.70.0 or later

immediate IT Operations

CVE-2025-9548

Detection coverage 1

Detect Potential CVE-2025-9548 PoC Execution

medium

Detects execution of the CVE-2025-9548 PoC tool by monitoring process creation with command-line arguments matching the known trigger flags.

sigma tactics: execution techniques: T1059.003 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →