1. Vulnerability Details
|
CVE-ID |
|
|
Description |
A zero-day security vulnerability, “Improper Link Resolution Before File Access,” was identified in the Nomad module of the 1E Client versions prior to 25.3. This vulnerability allows an attacker with local, unprivileged access on a Windows system to delete arbitrary files by exploiting symbolic links.
– 1E Client v25.1 – hotfix Q23589 or later |
|
CVSS3.1 Score |
Base Score 7.8 (High) |
|
CVSS3.1 Vector String |
|
|
Problem type |
2. Affected products and versions
|
Product
|
Versions
|
|---|---|
|
1E Client – Nomad Module |
Prior 25.3 |
|
1E Content Distribution Tools v25.1 |
Prior 25.3 |