CVE-2025-1729: Lenovo Trackpoint Quick Menu
Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.
A DLL hijacking vulnerability was reported in TrackPoint Quick Menu software that, under certain conditions, could allow a local attacker to escalate privileges.
Affected products
- Lenovo Trackpoint Quick Menu: before 1.12.54.0 (fixed in 1.12.54.0)
Published 2025-07-17. Last modified 2026-06-17.