Metrics
Affected Vendors & Products
No advisories yet.
Solution
Lenovo One is no longer supported and customers should discontinue use. Lenovo recommends that customers download Smart Connect from the Microsoft Store.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://iknow.lenovo.com.cn/detail/435007 |
|
| https://one.lenovo.com/ |
|
Wed, 10 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Dec 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that could allow a local authenticated user to execute code with elevated privileges. | |
| First Time appeared |
Lenovo
Lenovo one Client |
|
| Weaknesses | CWE-427 | |
| CPEs | cpe:2.3:a:lenovo:one_client:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lenovo
Lenovo one Client |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2025-12-10T15:17:35.256Z
Reserved: 2025-11-13T21:26:42.588Z
Link: CVE-2025-13152
Updated: 2025-12-10T15:17:30.990Z
Status : Awaiting Analysis
Published: 2025-12-10T15:15:56.410
Modified: 2025-12-12T15:18:42.140
Link: CVE-2025-13152
No data.
OpenCVE Enrichment
No data.