CVE-2025-1729: Lenovo Trackpoint Quick Menu

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

A DLL hijacking vulnerability was reported in TrackPoint Quick Menu software that, under certain conditions, could allow a local attacker to escalate privileges.

Affected products

  • Lenovo Trackpoint Quick Menu: before 1.12.54.0 (fixed in 1.12.54.0)

Published 2025-07-17. Last modified 2026-06-17.