CVE-2025-13154PoC

LOWCVSS 6.8 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

An improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-02-10); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-10: 1Mentions · 2026-02-13: 1Mentions · 2026-03-11: 1PoC Mentioned / Linked · 2026-02-10: 1Patch / Workaround · 2026-03-11: 1Technical Details · 2026-02-10: 102-1002-1303-11
Signal classification3 categories
PoC
133.3%
General
133.3%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-101
PoC1
2026-02-131
General1
2026-03-111
Patch1
Full discourse3 posts
  • Compass Security@compasssecurity
    PoC

    John Ostrowski (Compass Security) and Manuel Kiesel (Cyllective AG) worked together on CVE-2025-13154, a Lenovo Vantage LPE. Even after Microsoft closed a known primitive, collaboration led to a working PoC. https://blog.compass-security.com/2026/02/from-folder-deletion-to-admin-lenovo-vantage-cve-2025-13154/ #Windows #CVE #SecurityResearch #PrivEsc https://t.co/dxVlhtf9Zb

    Post summary

    John Ostrowski and Manuel Kiesel collaborated on CVE-2025-13154, a Lenovo Vantage local privilege escalation vulnerability, and produced a working proof‑of‑concept.

    218052154.9K
    3.2K followersView on X
  • cy//ective@cyllective
    Patch

    Lenovo released all patches for the #Lenovo #Vantage #vulnerabilities, which we've reported earlier this year. Our blog now includes the full write‑ups for CVE-2025-13154, CVE-2026-1715, CVE-2026-1716, and CVE-2026-1717. 🔗 https://cyllective.com/blog/posts/lenovo-vantage/

    Post summary

    Lenovo announced the release of patches for four Vantage vulnerabilities, with a blog now containing detailed write‑ups for those CVEs.

    01010158
    532 followersView on X
  • cy//ective@cyllective
    General

    Two great follow‑ups expanding on our CVE‑2025‑13154 write‑up: 🔹 Manuel Kiesel (@rtfmkiesel) - "Roll with Advantage" 👉 https://mkiesel.ch/posts/lenovo-vantage/ 🔹 Compass Security (@compasssecurity) - "From Folder Deletion to Admin" 👉 https://blog.compass-security.com/2026/02/from-folder-deletion-to-admin-lenovo-vantage-cve-2025-13154/

    Post summary

    The message simply points to two follow‑up blog posts that expand on a prior write‑up of CVE‑2025‑13154, with no new PoC, exploit code, patch, or active exploitation details.

    0101085
    532 followersView on X

Explore more