CVE-2025-29837Link Following in Microsoft Windows 10 Version 1507

CWE-59Link Following5 documents5 sources
Severity
5.5MEDIUMNVD
EPSS
1.4%
top 19.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 13

Description

Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages26 packages

NVDmicrosoft/windows< 10.0.14393.8066+5
NVDmicrosoft/windows_10_1507< 10.0.10240.21014
NVDmicrosoft/windows_10_1607< 10.0.14393.8066
NVDmicrosoft/windows_10_1809< 10.0.17763.7314
NVDmicrosoft/windows_10_21h2< 10.0.19044.5854

🔴Vulnerability Details

2
CVEList
Windows Installer Information Disclosure Vulnerability2025-05-13
GHSA
GHSA-xhg9-hf6j-8vpj: Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally2025-05-13

📋Vendor Advisories

1
Microsoft
Windows Installer Information Disclosure Vulnerability2025-05-13

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws2025-05-13
CVE-2025-29837 — Link Following in Microsoft | cvebase