Threats Tagged 'cve-2025-13155'
View all threats tagged with 'cve-2025-13155'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-13155'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2025-13155 is a high-severity vulnerability in the Lenovo Baiying Client caused by incorrect default permissions. It allows a local authenticated user to execute code with elevated privileges without requiring user interaction. The vulnerability stems from improper permission settings (CWE-276), enabling privilege escalation on affected systems. Although no exploits are currently known in the wild, the CVSS 8.5 score indicates a significant risk. This issue primarily affects local users who already have some access but can leverage this flaw to gain higher privileges. European organizations using Lenovo Baiying Client should be vigilant, especially in sectors with sensitive data or critical infrastructure. Mitigation involves auditing and correcting file and resource permissions, applying vendor patches once available, and restricting local user privileges. Countries with high Lenovo market penetration and strategic industries, such as Germany, France, and the UK, are most likely to be impacted. Immediate action is recommended to prevent potential exploitation and privilege escalation attacks. Join the discussion | CVE Database V5 | 12/10/2025, 14:08:56 UTC Added: 12/10/2025, 14:22:54 UTC |
Showing 1 to 1 of 1 result