CVE-2020-28407: Swtpm Project Swtpm

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.

Affected products

  • Swtpm Project Swtpm: before 0.4.2 (fixed in 0.4.2); version 0.5.0 only

Published 2023-11-03. Last modified 2026-06-17.