Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivileged access on a Windows system to delete arbitrary files on the device by exploiting symbolic links.
History

Thu, 13 Mar 2025 10:15:00 +0000

Type Values Removed Values Added
Title Symbolic Link Exploit in Nomad module allows Arbitrary File Deletion Symbolic Link Exploit in 1E Client's - Nomad module allows Arbitrary File Deletion
References

Wed, 12 Mar 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Link Resolution Before File Access in the Nomad module of the 1E Client prior to versions 25.3, allows an attacker with local unprivileged access on a Windows system to delete arbitrary files on the device by abusing symbolic links. Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivileged access on a Windows system to delete arbitrary files on the device by exploiting symbolic links.
Title 1E Nomad Arbitrary File Deletion Symbolic Link Exploit in Nomad module allows Arbitrary File Deletion
References

Wed, 12 Mar 2025 15:30:00 +0000

Type Values Removed Values Added
Description Improper Link Resolution Before File Access in the Nomad module of the 1E Client prior to versions 25.3, allows an attacker with local unprivileged access on a Windows system to delete arbitrary files on the device by abusing symbolic links.
Title 1E Nomad Arbitrary File Deletion
Weaknesses CWE-59
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: 1E

Published:

Updated: 2025-03-13T10:09:29.980Z

Reserved: 2025-02-25T10:27:23.761Z

Link: CVE-2025-1683

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-12T16:15:20.660

Modified: 2025-03-13T10:15:19.687

Link: CVE-2025-1683

cve-icon Redhat

No data.