Skip to main content

Threats Tagged 'cve-2025-13155'

View all threats tagged with 'cve-2025-13155'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2025-13155

Threats Tagged 'cve-2025-13155'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2025-13155 is a high-severity vulnerability in the Lenovo Baiying Client caused by incorrect default permissions. It allows a local authenticated user to execute code with elevated privileges without requiring user interaction. The vulnerability stems from improper permission settings (CWE-276), enabling privilege escalation on affected systems. Although no exploits are currently known in the wild, the CVSS 8.5 score indicates a significant risk. This issue primarily affects local users who already have some access but can leverage this flaw to gain higher privileges. European organizations using Lenovo Baiying Client should be vigilant, especially in sectors with sensitive data or critical infrastructure. Mitigation involves auditing and correcting file and resource permissions, applying vendor patches once available, and restricting local user privileges. Countries with high Lenovo market penetration and strategic industries, such as Germany, France, and the UK, are most likely to be impacted. Immediate action is recommended to prevent potential exploitation and privilege escalation attacks.

Join the discussion

Showing 1 to 1 of 1 result

Filters:Tag: cve-2025-13155
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses