CVE-2025-1729 - Privilege Escalation Using TPQMAssistant.exe
ID: 4d0984a6-f439-59a4-a11f-5f1b0984f9ae
STIX ID: report--4d0984a6-f439-59a4-a11f-5f1b0984f9ae
Feed Name: TrustedSec blog
A researcher discovered a local DLL sideloading vulnerability in Lenovo's TrackPoint Quick Menu where TPQMAssistant.exe (scheduled to run daily under the logged-in user) attempts to load hostfxr.dll from a user-writable C:\ProgramData\Lenovo\TPQM directory; by planting a malicious hostfxr.dll a standard user can achieve code execution that will run when an administrator later logs in, enabling potential privilege escalation. The researcher provided PoC evidence, coordinated disclosure with Lenovo PSIRT, and Lenovo issued a UWP-based update and a planned system update to remove the vulnerable win32 scheduler.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
