
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13154 is an improper link following (symlink) vulnerability in the SmartPerformanceAddin component of Lenovo Vantage that allows an authenticated local user to perform arbitrary file deletion with elevated privileges. The vulnerability affects Lenovo Vantage versions prior to 1.1.0.1111 and was published on January 14, 2026. It carries a CVSS v3.1 base score of 5.5 (Medium) and a CVSS v4.0 base score of 6.8 (Medium) (Lenovo Advisory, Red Hat CVE).
The root cause is classified as CWE-59 (Improper Link Resolution Before File Access — 'Link Following'), where the SmartPerformanceAddin component fails to properly validate symbolic links before performing privileged file operations. An authenticated local attacker can plant a symlink pointing to an arbitrary target file, which the elevated-privilege service then follows and deletes. The attack vector is local, requires low privileges, no user interaction, and low attack complexity, making it straightforward to exploit once local access is obtained. A detailed technical write-up by Compass Security describes the escalation path from folder deletion to administrator-level impact (Compass Security Blog, Cyllective Blog).
Successful exploitation allows an authenticated local attacker to delete arbitrary files on the system with elevated (administrator-level) privileges, resulting in a high availability impact. While confidentiality and integrity are not directly impacted per the CVSS scoring, deletion of critical system files, security tools, or application binaries can lead to denial of service, system instability, or serve as a stepping stone for privilege escalation to full administrator access as detailed in public research (Compass Security Blog, Cyllective Blog).
mklink (Windows built-in) or a symlink-creation utility, replace or create a symbolic link at the expected path that points to an arbitrary target file (e.g., a critical system file or security tool binary): mklink /D C:\Path\To\Monitored\Folder C:\Windows\System32\TargetFile.LenovoVantage.exe or related SmartPerformanceAddin process) targeting unexpected file paths; audit logs recording symlink creation by a low-privileged user account.mklink or similar symlink-creation commands executed by non-administrative users in process creation logs (Event ID 4688).Lenovo has released a patched version of Lenovo Vantage (SmartPerformanceAddin version 1.1.0.1111 or later) that addresses this vulnerability. Users should update Lenovo Vantage via the Microsoft Store or Lenovo's official update mechanism as soon as possible. No specific configuration-based workaround has been published; the primary remediation is upgrading to the fixed version (Lenovo Advisory).
Compass Security published a detailed technical blog post titled "From Folder Deletion to Admin: Lenovo Vantage CVE-2025-13154" in February 2026, demonstrating how the symlink vulnerability can be chained to achieve administrator-level access (Compass Security Blog). Cyllective also published a blog post covering the vulnerability with technical analysis (Cyllective Blog). Social media activity on Bluesky noted the disclosure, though overall community reaction has been moderate given the local-only attack vector.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."