CVE-2025-13155

7.8

Lenovo · Baiying Client

Lenovo Baiying Client contains an improper permissions vulnerability that allows a local authenticated user to execute code with elevated privileges.

Executive summary

A local privilege escalation vulnerability in Lenovo Baiying Client allows authenticated users to execute arbitrary code with higher privileges, posing a significant risk to system integrity.

Vulnerability

This vulnerability is caused by incorrect default permissions, which may allow a local authenticated user to manipulate the application and achieve code execution with elevated privileges.

Business impact

The ability for a local user to escalate privileges to the level of the application provides an attacker with a foothold to compromise system security, potentially leading to unauthorized data access or complete system takeover. With a CVSS score of 7.8, this vulnerability represents a High severity risk that must be addressed to prevent lateral movement and privilege abuse within the environment.

Remediation

Immediate Action: Update the Lenovo Baiying Client to version 4.1.0 or later to resolve the underlying permission configuration issue.

Proactive Monitoring: Audit system logs for unexpected process execution or modifications to application binaries that may indicate an attempt to exploit local permissions.

Compensating Controls: Restrict local user access to the affected system and enforce the principle of least privilege to minimize the potential for non-privileged accounts to interact with sensitive services.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for privilege escalation and the availability of a vendor-provided patch, administrators should prioritize updating all instances of the Lenovo Baiying Client to version 4.1.0. Failure to update leaves local users with the ability to bypass security constraints and execute unauthorized code, which is a critical risk for multi-user environments.

More Lenovo CVEs

Sources

Originally found and disclosed by Lenovo thanks Wanjie from Huazhong University of Science and Technology for reporting this issue., per the CVE Program record.