CVE-2025-1683
Symbolic Link Exploit in 1E Client's - Nomad module allows Arbitrary File Deletion
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.8EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
12 Mar 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivileged access on a Windows system to delete arbitrary files on the device by exploiting symbolic links.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
1E · 1E ClientWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →