CVE-2020-28407: Swtpm Project Swtpm
High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.
In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.
Affected products
- Swtpm Project Swtpm: before 0.4.2 (fixed in 0.4.2); version 0.5.0 only
Published 2023-11-03. Last modified 2026-06-17.