A potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that could allow a local authenticated user to execute code with elevated privileges.
Advisories

No advisories yet.

Fixes

Solution

Lenovo One is no longer supported and customers should discontinue use. Lenovo recommends that customers download Smart Connect from the Microsoft Store.


Workaround

No workaround given by the vendor.

History

Wed, 10 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 10 Dec 2025 14:30:00 +0000

Type Values Removed Values Added
Description A potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that could allow a local authenticated user to execute code with elevated privileges.
First Time appeared Lenovo
Lenovo one Client
Weaknesses CWE-427
CPEs cpe:2.3:a:lenovo:one_client:*:*:*:*:*:*:*:*
Vendors & Products Lenovo
Lenovo one Client
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2025-12-10T15:17:35.256Z

Reserved: 2025-11-13T21:26:42.588Z

Link: CVE-2025-13152

cve-icon Vulnrichment

Updated: 2025-12-10T15:17:30.990Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-10T15:15:56.410

Modified: 2025-12-12T15:18:42.140

Link: CVE-2025-13152

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses