arbitrary data to be written to protected locations, potentially leading to escalation of privilege, arbitrary file
corruption, exposure of application and system information or persistent denial of service when a low-privileged
attacker tampers with the installation folder.
Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2025-28481 | CWE-59: Improper Link Resolution Before File Access ('Link Following') vulnerability exists that could cause arbitrary data to be written to protected locations, potentially leading to escalation of privilege, arbitrary file corruption, exposure of application and system information or persistent denial of service when a low-privileged attacker tampers with the installation folder. | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 18 Aug 2025 21:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Schneider-electric
         Schneider-electric software Update Utility  | 
|
| Vendors & Products | 
        
        Schneider-electric
         Schneider-electric software Update Utility  | 
Mon, 18 Aug 2025 13:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Mon, 18 Aug 2025 07:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | CWE-59: Improper Link Resolution Before File Access ('Link Following') vulnerability exists that could cause arbitrary data to be written to protected locations, potentially leading to escalation of privilege, arbitrary file corruption, exposure of application and system information or persistent denial of service when a low-privileged attacker tampers with the installation folder. | |
| Weaknesses | CWE-59 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
 
  | 
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2025-08-18T12:22:22.123Z
Reserved: 2025-05-28T06:06:42.804Z
Link: CVE-2025-5296
Updated: 2025-08-18T12:22:19.212Z
Status : Awaiting Analysis
Published: 2025-08-18T08:15:27.820
Modified: 2025-08-18T20:16:28.750
Link: CVE-2025-5296
No data.
                        OpenCVE Enrichment
                    Updated: 2025-08-18T21:20:46Z
 EUVD