CVE-2025-6232
published 2025-07-17CVE-2025-6232: An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.18%
7.8th percentile
An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying specific registry locations.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lenovo | commercial_vantage | < 20.2506.39.0 | 20.2506.39.0 |
| lenovo | vantage | < 10.2501.20.0 | 10.2501.20.0 |
| msrc | azl3_python3_3.12.3-4_on_azure_linux_3.0 | — | — |
| msrc | azl3_python3_3.12.3-5_on_azure_linux_3.0 | — | — |
| msrc | azl3_tensorflow_2.16.1-7_on_azure_linux_3.0 | — | — |
| msrc | azl3_tensorflow_2.16.1-9_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_python3_3.9.19-13_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python3_3.9.19-5_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.5HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7wq6-wxf9-cp78: An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with el
ghsa_unreviewed·2025-07-17
CVE-2025-6232 [HIGH] CWE-88 GHSA-7wq6-wxf9-cp78: An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with el
An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying specific registry locations.
Microsoft
Regular-expression DoS when parsing TarFile headers
vendor_msrc·2024-09-10·CVSS 7.5
CVE-2024-6232 [HIGH] CWE-1333 Regular-expression DoS when parsing TarFile headers
Regular-expression DoS when parsing TarFile headers
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
PSF: PSF
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microso
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-13154 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2025-13154 [MEDIUM] CVE-2025-13154 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-13154 :
Lenovo Vantage vulnerability analysis and mitigation
An improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.
Source : NVD
## 6.8
Score
Published January 14, 2026
Severity MEDIUM
CNA Score 6.8
Affected Technologies
Lenovo Vantage
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:lenovo:vantage
Sources
NVD
Windows Severity MEDIUM Has Fix Added at: Jan 18, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cl
Wiz
CVE-2026-1717 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2026-1717 [MEDIUM] CVE-2026-1717 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1717 :
Lenovo Vantage vulnerability analysis and mitigation
An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to terminate arbitrary processes with elevated privileges.
Source : NVD
## 6.8
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 6.8
Affected Technologies
Lenovo Vantage
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:lenovo:vantage
Sources
Windows Severity MEDIUM Has Fix Added at: Mar 19, 2026
Windows Severity MEDIUM Has Fix Added at: Mar 29, 2026
## G
Wiz
CVE-2026-1716 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2026-1716 [MEDIUM] CVE-2026-1716 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1716 :
Lenovo Vantage vulnerability analysis and mitigation
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to delete arbitrary registry keys with elevated privileges.
Source : NVD
## 6.9
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 6.9
Affected Technologies
Lenovo Vantage
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:lenovo:vantage
Sources
Windows Severity HIGH Has Fix Added at: Mar 19, 2026
Windows Severity HIGH Has Fix Added at: Mar 29, 2026
## Get a CV
Wiz
CVE-2026-1715 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2026-1715 [MEDIUM] CVE-2026-1715 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1715 :
Lenovo Vantage vulnerability analysis and mitigation
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to modify arbitrary registry keys with elevated privileges.
Source : NVD
## 6.9
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 6.9
Affected Technologies
Lenovo Vantage
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:lenovo:vantage
Sources
Windows Severity HIGH Has Fix Added at: Mar 19, 2026
Windows Severity HIGH Has Fix Added at: Mar 29, 2026
## Get a CV
2025-07-17
Published