CVE-2025-7376
Windows Shortcut Following (.LNK) vulnerability in multiple processes of Mitsubishi Electric Iconics Digital Solutions GENESIS64 all versions, Mitsubishi Electric Iconics Digital Solutions GENESIS version 11.00, Mitsubishi Electric GENESIS64 all versions, Mitsubishi Electric MC Works64 all versions, and Mitsubishi Electric GENESIS version 11.00 allows a local authenticated attacker to make an unauthorized write to arbitrary files, by creating a symbolic link from a file used as a write destination by the processes of the affected products to a target file. This could allow the attacker to destroy the file on a PC with the affected products installed, resulting in a denial-of-service (DoS) condition on the PC if the destroyed file is necessary for the operation of the PC.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.9
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N
- EPSS probability
- 0.20%
- CWE
- CWE-64
- Published
- 2025-08-06
- Last modified
- 2026-04-10
Affected products
- Mitsubishi Electric Corporation GENESIS64
- Mitsubishi Electric Corporation MC Works64
- Mitsubishi Electric Iconics Digital Solutions GENESIS64
- Mitsubishi Electric Corporation GENESIS
- Mitsubishi Electric Iconics Digital Solutions GENESIS
- Mitsubishi Electric Corporation GENESIS64
- Mitsubishi Electric Iconics Digital Solutions GENESIS64
- Mitsubishi Electric Corporation ICONICS Suite
Weakness type
Related vulnerabilities
- CVE-2025-53503 — Trend Micro Cleaner One Pro is vulnerable to a Privilege Escalation vulnerability that could allow...
- CVE-2025-52837 — Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link...
- CVE-2025-52521 — Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation...
- CVE-2025-49385 — Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation...
- CVE-2025-49384 — Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation...
- CVE-2025-48443 — Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link...
- CVE-2021-41562 — Deletion of arbitrary files vulnerability in Snow Agent for Windows
- CVE-2021-1492 — Duo Authentication Proxy Installer Denial of Service Vulnerability