CVE-2025-4211: Improper Link Resolution Before File Access in QFileSystemEngine on Windows

Published May 16, 2025
·
Updated

Improper Link Resolution Before File Access ('Link Following') vulnerability in QFileSystemEngine in the Qt corelib module on Windows which potentially allows Symlink Attacks and the use of Malicious Files. Issue originates from CVE-2024-38081. The vulnerability arises from the use of the GetTempPath API, which can be exploited by attackers to manipulate temporary file paths, potentially leading to unauthorized access and privilege escalation. The affected public API in the Qt Framework is QDir::tempPath() and anything that uses it, such as QStandardPaths with TempLocation, QTemporaryDir, and QTemporaryFile.

This issue affects all version of Qt up to and including 5.15.18, from 6.0.0 through 6.5.8, from 6.6.0 through 6.8.1. It is fixed in Qt 5.15.19, Qt 6.5.9, Qt 6.8.2, 6.9.0

Affected Software

3 affected components
Qt Qt (corelib) QFileSystemEngine<=5.15.18
Qt Qt (corelib) QFileSystemEngine>=6.0.0<=6.5.8
Qt Qt (corelib) QFileSystemEngine>=6.6.0<=6.8.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Qt corelib (QFileSystemEngine on Windows) to a version that resolves this vulnerability.

    Fixed in 5.15.19
  2. Upgrade

    Upgrade Qt corelib (QFileSystemEngine on Windows) to a version that resolves this vulnerability.

    Fixed in 6.5.9
  3. Upgrade

    Upgrade Qt corelib (QFileSystemEngine on Windows) to a version that resolves this vulnerability.

    Fixed in 6.8.2
  4. Upgrade

    Upgrade Qt corelib (QFileSystemEngine on Windows) to a version that resolves this vulnerability.

    Fixed in 6.9.0

Event History

May 16, 2025
CVE Published
via MITRE·01:25 PM
Data Sourced
via MITRE·01:25 PM
DescriptionWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-4211?

CVE-2025-4211 is classified as a high-severity vulnerability due to its potential for allowing symlink attacks.

2

How do I fix CVE-2025-4211?

To mitigate CVE-2025-4211, you should update the Qt Framework to a version later than 5.15.18 or 6.5.8 and avoid using vulnerable applications until patched.

3

What types of software are affected by CVE-2025-4211?

CVE-2025-4211 affects the Qt Framework, specifically versions up to and including 5.15.18, between 6.0.0 and 6.5.8, and between 6.6.0 and 6.8.1.

4

What are the potential risks associated with CVE-2025-4211?

The risk associated with CVE-2025-4211 includes unauthorized access to files and potential exploitation of system resources through malicious file links.

5

When was CVE-2025-4211 introduced?

CVE-2025-4211 is derived from CVE-2024-38081, indicating a pre-existing issue that has been identified and classified.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203