CVE-2025-13154
Lenovo Vantage vulnerability analysis and mitigation

Overview

CVE-2025-13154 is an improper link following (symlink) vulnerability in the SmartPerformanceAddin component of Lenovo Vantage that allows an authenticated local user to perform arbitrary file deletion with elevated privileges. The vulnerability affects Lenovo Vantage versions prior to 1.1.0.1111 and was published on January 14, 2026. It carries a CVSS v3.1 base score of 5.5 (Medium) and a CVSS v4.0 base score of 6.8 (Medium) (Lenovo Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-59 (Improper Link Resolution Before File Access — 'Link Following'), where the SmartPerformanceAddin component fails to properly validate symbolic links before performing privileged file operations. An authenticated local attacker can plant a symlink pointing to an arbitrary target file, which the elevated-privilege service then follows and deletes. The attack vector is local, requires low privileges, no user interaction, and low attack complexity, making it straightforward to exploit once local access is obtained. A detailed technical write-up by Compass Security describes the escalation path from folder deletion to administrator-level impact (Compass Security Blog, Cyllective Blog).

Impact

Successful exploitation allows an authenticated local attacker to delete arbitrary files on the system with elevated (administrator-level) privileges, resulting in a high availability impact. While confidentiality and integrity are not directly impacted per the CVSS scoring, deletion of critical system files, security tools, or application binaries can lead to denial of service, system instability, or serve as a stepping stone for privilege escalation to full administrator access as detailed in public research (Compass Security Blog, Cyllective Blog).

Exploitation steps

  1. Gain Local Access: Obtain an authenticated local user session on a Windows system running Lenovo Vantage with SmartPerformanceAddin version prior to 1.1.0.1111.
  2. Identify Target Path: Determine the directory or file path that the SmartPerformanceAddin service operates on with elevated privileges during its cleanup or performance optimization routines.
  3. Create Symbolic Link: Using a tool such as mklink (Windows built-in) or a symlink-creation utility, replace or create a symbolic link at the expected path that points to an arbitrary target file (e.g., a critical system file or security tool binary): mklink /D C:\Path\To\Monitored\Folder C:\Windows\System32\TargetFile.
  4. Trigger Privileged Operation: Initiate or wait for the SmartPerformanceAddin service to perform its file deletion routine, which follows the symlink and deletes the attacker-specified target file with elevated privileges.
  5. Achieve Objective: Leverage the deletion of critical files (e.g., security software, system binaries) to cause denial of service or create conditions for further privilege escalation to administrator (Compass Security Blog, Cyllective Blog).

Indicators of compromise

  • File System: Unexpected symbolic links (junctions or symlinks) in directories monitored or cleaned by the Lenovo Vantage SmartPerformanceAddin service; missing or deleted critical system files or security tool binaries that should not have been removed.
  • Logs: Windows Event Logs (Security/System) showing file deletion events originating from the Lenovo Vantage service process (LenovoVantage.exe or related SmartPerformanceAddin process) targeting unexpected file paths; audit logs recording symlink creation by a low-privileged user account.
  • Process: Lenovo Vantage service processes performing file operations on paths outside their expected working directories; mklink or similar symlink-creation commands executed by non-administrative users in process creation logs (Event ID 4688).

Mitigation and workarounds

Lenovo has released a patched version of Lenovo Vantage (SmartPerformanceAddin version 1.1.0.1111 or later) that addresses this vulnerability. Users should update Lenovo Vantage via the Microsoft Store or Lenovo's official update mechanism as soon as possible. No specific configuration-based workaround has been published; the primary remediation is upgrading to the fixed version (Lenovo Advisory).

Community reactions

Compass Security published a detailed technical blog post titled "From Folder Deletion to Admin: Lenovo Vantage CVE-2025-13154" in February 2026, demonstrating how the symlink vulnerability can be chained to achieve administrator-level access (Compass Security Blog). Cyllective also published a blog post covering the vulnerability with technical analysis (Cyllective Blog). Social media activity on Bluesky noted the disclosure, though overall community reaction has been moderate given the local-only attack vector.

Additional resources


SourceThis report was generated using AI

Related Lenovo Vantage vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-0827MEDIUM6.9
  • Lenovo Vantage logoLenovo Vantage
  • cpe:2.3:a:lenovo:vantage
NoYesApr 15, 2026
CVE-2026-1716MEDIUM6.9
  • Lenovo Vantage logoLenovo Vantage
  • cpe:2.3:a:lenovo:vantage
NoYesMar 11, 2026
CVE-2026-1715MEDIUM6.9
  • Lenovo Vantage logoLenovo Vantage
  • cpe:2.3:a:lenovo:vantage
NoYesMar 11, 2026
CVE-2026-1717MEDIUM6.8
  • Lenovo Vantage logoLenovo Vantage
  • cpe:2.3:a:lenovo:vantage
NoYesMar 11, 2026
CVE-2025-13154MEDIUM6.8
  • Lenovo Vantage logoLenovo Vantage
  • cpe:2.3:a:lenovo:vantage
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management