#VU112076 Link following in Qt - CVE-2025-4211
Published: July 1, 2025
Qt
Trolltech
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an insecure link following issue within QFileSystemEngine in the Qt corelib module on Windows. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.