CVE-2025-13152: High severity Lenovo One Client vulnerability
A potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that could allow a local authenticated user to execute code with elevated privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Lenovo One Clientfrom your environment.Discontinue use of Lenovo One Client because it is no longer supported.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13152?
CVE-2025-13152 has a medium severity level due to its potential for local privilege escalation.
How do I fix CVE-2025-13152?
To mitigate CVE-2025-13152, ensure you are using the latest version of Lenovo One Client that includes security updates.
Who is affected by CVE-2025-13152?
CVE-2025-13152 affects local authenticated users of Lenovo One Client.
What type of vulnerability is CVE-2025-13152?
CVE-2025-13152 is classified as a DLL hijacking vulnerability.
Can CVE-2025-13152 be exploited remotely?
No, CVE-2025-13152 requires local authenticated access to be exploited.