CVE-2025-1683: 1e Platform
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivileged access on a Windows system to delete arbitrary files on the device by exploiting symbolic links.
Affected products
- 1e Platform: before 25.3 (fixed in 25.3)
Published 2025-03-12. Last modified 2026-06-17.