{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3alenovopower_management_driver/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:lenovo:power_management_driver:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":5.5,"id":"CVE-2025-9548"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Power Management Driver (\u003c 1.69.70.0)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","windows","hardware-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Lenovo"],"content_html":"\u003cp\u003eCVE-2025-9548 is a null pointer dereference vulnerability residing in the Lenovo Power Management Driver (pmdrvs.sys) affecting versions prior to 1.69.70.0. The vulnerability allows an authenticated local user with sufficient privileges to send a crafted IOCTL request to the driver interface, triggering an unhandled exception that results in a system crash (Blue Screen of Death). The researcher, Sam Dalgleish, publicly released a proof-of-concept (PoC) tool on October 10, 2026, which demonstrates the ability to invoke the crash by sending IOCTL 0x802B2243 to the device object '\\.\\pmdrvs'. While the vulnerability is limited to a local denial of service and does not inherently provide privilege escalation or arbitrary code execution, the availability of functional exploit code increases the risk for unpatched enterprise workstations and laptops.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in an immediate system-wide denial of service, forcing a reboot and potential data loss for any user with active sessions. The vulnerability affects a broad range of Lenovo hardware utilizing the affected Power Management Driver versions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch all Lenovo systems immediately by upgrading the Power Management Driver to version 1.69.70.0 or later.\u003c/li\u003e\n\u003cli\u003eAudit high-availability or critical workstations for the presence of pmdrvs.sys versions earlier than 1.69.70.0.\u003c/li\u003e\n\u003cli\u003eDeploy detection logic to identify the execution of the identified PoC or similar attempts to interface with the vulnerable driver IOCTL interface.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-10T17:00:20Z","date_published":"2026-10-10T17:00:20Z","id":"https://feed.craftedsignal.io/briefs/2026-10-lenovo-pmdrvs-dos/","summary":"An authenticated local user can trigger a system-wide denial of service by exploiting a null pointer dereference vulnerability in the Lenovo Power Management Driver, pmdrvs.sys.","title":"Denial of Service in Lenovo Power Management Driver (CVE-2025-9548)","url":"https://feed.craftedsignal.io/briefs/2026-10-lenovo-pmdrvs-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:lenovo:power_management_driver:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}