PT-2025-21651 · Qt Company · Qt
CVE-2025-4211
·
Published
2025-05-16
·
Updated
2026-07-29
CVSS v4.0
7.3
High
| Vector | AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Qt versions prior to 5.15.19
Qt versions 6.0.0 through 6.5.8
Qt versions 6.6.0 through 6.8.1
Description
An improper link resolution issue exists in QFileSystemEngine within the Qt corelib module on Windows. This flaw arises from the use of the
GetTempPath API, which allows attackers to manipulate temporary file paths. This can lead to symlink attacks, the use of malicious files, unauthorized access, and privilege escalation. The affected public API is QDir::tempPath() and any components utilizing it, including QStandardPaths with TempLocation, QTemporaryDir, and QTemporaryFile.Recommendations
Update to version 5.15.19.
Update to version 6.5.9.
Update to version 6.8.2.
Update to version 6.9.0.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qt