| CVE ID | |
| CVSS SCORE | 3.3, AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
| AFFECTED VENDORS |
Microsoft |
| AFFECTED PRODUCTS |
Windows |
| VULNERABILITY DETAILS |
This vulnerability allows remote attackers to disguise hard links on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the rendering of the contents of TAR files. Windows displays hard links within TAR files without providing any visual indication to differentiate them from normal files. An attacker can leverage this vulnerability to deceive a user regarding the trustworthiness of a file. |
| ADDITIONAL DETAILS |
07/25/25 - ZDI reported the vulnerability to the vendor -- Mitigation: Given the nature of the vulnerability, the only salient mitigation strategy is to restrict interaction with the product |
| DISCLOSURE TIMELINE |
|
| CREDIT | Len Sadowski and Oguz Bektas |