Lenovo disclosed CVE-2025-13154, an improper link following vulnerability in the SmartPerformanceAddin component of Lenovo Vantage that could let an authenticated local user delete arbitrary files with elevated privileges. The company said the flaw could lead to denial of service and privilege escalation, rated it Medium severity, and described the impact as Lenovo-specific. Lenovo credited Alex Lee Tsz Hin of PwCHK and Manuel Kiesel of cyllective AG together with John Ostrowski of Compass Security for reporting the issue.
Lenovo advised customers to update Vantage SmartPerformanceAddin to version 1.1.0.1111 or later, noting that the component is normally updated automatically through Lenovo Vantage. Separate Lenovo and Intel advisories in the same set also reference security issues affecting Intel Ethernet adapters and controllers, including Intel advisory INTEL-SA-00918, indicating ongoing vendor remediation activity across Lenovo-supported hardware and software components.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Lenovo published advisory LEN-208293 for CVE-2025-13154, an improper link following flaw in the SmartPerformanceAddin component for Lenovo Vantage that could let an authenticated local user delete arbitrary files with elevated privileges. Lenovo rated the issue Medium severity and advised updating SmartPerformanceAddin to version 1.1.0.1111 or later; the issue was reported by Alex Lee Tsz Hin, Manuel Kiesel, and John Ostrowski.
Intel released security advisory INTEL-SA-00918, disclosing a security issue tracked by Intel in its products. The reference indicates this was an official vendor advisory publication.
Lenovo published security advisory LEN-115703 concerning Intel Ethernet Adapters and the Intel Ethernet Controller I225. The advisory indicates Lenovo disclosed product security information related to affected Intel Ethernet components.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
support.lenovo.com
Open sourceintel.com
Open sourcesupport.lenovo.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.