CVE-2025-4211 - CVE House
Back to Database
Status published High CVE-2025-4211

Improper Link Resolution Before File Access in QFileSystemEngine on Windows

Vulnerability Description

Improper Link Resolution Before File Access ('Link Following') vulnerability in QFileSystemEngine in the Qt corelib module on Windows which potentially allows Symlink Attacks and the use of Malicious Files. Issue originates from CVE-2024-38081. The vulnerability arises from the use of the GetTempPath API, which can be exploited by attackers to manipulate temporary file paths, potentially leading to unauthorized access and privilege escalation. The affected public API in the Qt Framework is QDir::tempPath() and anything that uses it, such as QStandardPaths with TempLocation, QTemporaryDir, and QTemporaryFile.This issue affects all version of Qt up to and including 5.15.18, from 6.0.0 through 6.5.8, from 6.6.0 through 6.8.1. It is fixed in Qt 5.15.19, Qt 6.5.9, Qt 6.8.2, 6.9.0

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-4211

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

The Qt Company

View all reports →

Affected Software

Qt
Vulnerable Versions:
0, 6.0.0, 6.6.0

Timeline

Official Publish: May 16th, 2025
Last Modified: May 16th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)