« Volver al listado

CVE-2025-1683

Estado: AnalizadaAlta (7.8)—

Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivileged access on a Windows system to delete arbitrary files on the device by exploiting symbolic links.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Acceso local sin interacción (AV:L, UI:N, PR:L) en Windows permite escalada mediante symlink. El atacante logra eliminar archivos arbitrarios, manipulando datos/archivos del sistema.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-1683",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-1683",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-03-12T15:40:48.449073Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@1e.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@1e.com",
      "affectedData": [
        {
          "vendor": "1E",
          "modules": [
            "Nomad",
            "1EContentDistributionTools-NomadBranchTools"
          ],
          "product": "1E Client",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "MSP-Q23583",
                  "status": "unaffected"
                },
                {
                  "at": "MSP-Q23591",
                  "status": "unaffected"
                }
              ],
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "24.5"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "MSP-Q23589",
                  "status": "unaffected"
                },
                {
                  "at": "MSP-Q23591",
                  "status": "unaffected"
                }
              ],
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "25.1"
            },
            {
              "status": "unaffected",
              "version": "25.3",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Windows"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-03-12T16:15:20.660",
  "references": [
    {
      "url": "https://capec.mitre.org/data/definitions/27.html",
      "tags": [
        "Not Applicable"
      ],
      "source": "security@1e.com"
    },
    {
      "url": "https://cwe.mitre.org/data/definitions/59.html",
      "tags": [
        "Not Applicable"
      ],
      "source": "security@1e.com"
    },
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1683",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "security@1e.com"
    },
    {
      "url": "https://www.teamviewer.com/en/resources/trust-center/security-bulletins/1e-2025-2001/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@1e.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@1e.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-59"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivileged access on a Windows system to delete arbitrary files on the device by exploiting symbolic links."
    },
    {
      "lang": "es",
      "value": "La resolución de enlace incorrecta antes del acceso a archivos en el módulo Nomad del Cliente 1E, en versiones anteriores a la 25.3, permite a un atacante con acceso local sin privilegios en un sistema Windows eliminar archivos arbitrarios en el dispositivo mediante la explotación de enlaces simbólicos."
    }
  ],
  "lastModified": "2026-06-17T08:39:35.883",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:1e:platform:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "541FBA0F-DD56-44DF-996A-1D8BB6457D6C",
              "versionEndExcluding": "25.3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@1e.com"
}