CVE-2025-13152

7.8

Lenovo · One Client

A DLL hijacking vulnerability in Lenovo One Client allows a local authenticated user to execute code with elevated privileges via an uncontrolled search path.

Executive summary

Lenovo One Client contains a DLL hijacking vulnerability that enables local authenticated users to achieve elevated code execution, posing a significant security risk.

Vulnerability

This vulnerability, categorized as CWE-427, involves an uncontrolled search path element where the application improperly loads dynamic link libraries. An authenticated local user can exploit this behavior to execute malicious code with the privileges of the application.

Business impact

The ability for a local user to escalate privileges to the level of the application provides a direct path for full system compromise. Given the CVSS score of 7.8, this flaw represents a high risk to organizational security, as it facilitates lateral movement and unauthorized access to sensitive system resources.

Remediation

Immediate Action: Lenovo has officially declared that Lenovo One is no longer supported and recommends that all customers discontinue its use and migrate to Smart Connect, available via the Microsoft Store.

Proactive Monitoring: Security teams should audit system logs for unauthorized software installation or execution patterns originating from standard user accounts.

Compensating Controls: Restrict local user permissions to prevent the installation of unauthorized files and ensure that application directories are properly secured with restrictive access control lists.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Due to the lack of vendor support and the inherent risk of local privilege escalation, organizations must prioritize the immediate removal of Lenovo One Client from all endpoints. Transitioning to the recommended replacement, Smart Connect, is the only effective way to remediate this vulnerability and eliminate the associated exposure.

More Lenovo CVEs

Sources