logo

CVE-2025-1729 - Privilege Escalation Using TPQMAssistant.exe

ID: 4d0984a6-f439-59a4-a11f-5f1b0984f9ae

STIX ID: report--4d0984a6-f439-59a4-a11f-5f1b0984f9ae

Feed Name: TrustedSec blog

Threat Score
60/100

Date Published: 2025-07-08

Date Updated: 2026-05-01

...
...

A researcher discovered a local DLL sideloading vulnerability in Lenovo's TrackPoint Quick Menu where TPQMAssistant.exe (scheduled to run daily under the logged-in user) attempts to load hostfxr.dll from a user-writable C:\ProgramData\Lenovo\TPQM directory; by planting a malicious hostfxr.dll a standard user can achieve code execution that will run when an administrator later logs in, enabling potential privilege escalation. The researcher provided PoC evidence, coordinated disclosure with Lenovo PSIRT, and Lenovo issued a UWP-based update and a planned system update to remove the vulnerable win32 scheduler.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.