1E-2025-2001

Symbolic link exploit in 1E client

公告栏 ID
1E-2025-2001
Issue Date
2025年3月12日
最后更新时间
2025年3月13日
优先级
CVSS
7.8 (High)
受影响的产品
CVE-2025-1683
受影响的产品
1E Client – Nomad Module
1E Content Distribution Tools v25.1

1. Vulnerability Details

CVE-ID

Description

A zero-day security vulnerability, “Improper Link Resolution Before File Access,” was identified in the Nomad module of the 1E Client versions prior to 25.3. This vulnerability allows an attacker with local, unprivileged access on a Windows system to delete arbitrary files by exploiting symbolic links.

 

–  1E Client v25.1 – hotfix Q23589 or later
–  1E Client v24.5 – hotfix Q23583 or later
–  1E Content Distribution Tools v25.1 – hotfix Q23591 or later

CVSS3.1 Score

Base Score 7.8 (High)

CVSS3.1 Vector String

Problem type

2. Affected products and versions

Product Versions

1E Client – Nomad Module

Prior 25.3

1E Content Distribution Tools v25.1

Prior 25.3

Do you want to report a security issue?

TeamViewer’s security team will investigate every submission in our Vulnerability Disclosure Program.