CVE-2025-12341
7.8ermig1979 · AntiDupl
A link following vulnerability in the Delete Duplicate Image Handler component of AntiDupl allows local attackers to manipulate file operations.
Executive summary
A local link following vulnerability in AntiDupl versions up to 2.3.12 permits unauthorized file manipulation, posing a significant risk to system integrity.
Vulnerability
The flaw exists within the Delete Duplicate Image Handler component of the AntiDupl.NET.WinForms.exe executable. It involves improper handling of symbolic links, which allows a local, authenticated user to perform unauthorized file operations.
Business impact
Successful exploitation of this vulnerability allows an attacker with local access to manipulate files, potentially leading to unauthorized data modification or system instability. With a CVSS score of 7.8, this flaw represents a high-severity risk to local system security. Organizations must consider the potential for privilege escalation or data corruption if this tool is deployed on multi-user systems.
Remediation
Immediate Action: Since the vendor has not responded to disclosure, users are advised to restrict execution permissions for AntiDupl.NET.WinForms.exe to only necessary administrative or service accounts. Monitor the vendor's repository for any future security patches or updates that address this issue.
Proactive Monitoring: Review system logs for unusual file access patterns or unexpected symbolic link creation activity originating from the AntiDupl application.
Compensating Controls: Implement strict file system permissions on directories managed by AntiDupl to prevent unauthorized users from creating symbolic links that could be targeted by this vulnerability.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
Given the lack of vendor response and the presence of a proof-of-concept, users should treat this vulnerability with high priority on any system where AntiDupl is installed. Administrators should limit access to the application to trusted users and monitor the environment for evidence of file manipulation attempts until an official fix is provided.
Sources
Originally found and disclosed by Zeze7w (VulDB User), per the CVE Program record.
- VDB-330127 | ermig1979 AntiDupl Delete Duplicate Image AntiDupl.NET.WinForms.exe link following Vulnerability database entry
- VDB-330127 | CTI Indicators (IOB, IOC, IOA)
- Submit #674515 | AntiDupl 2.3.12 Link Following Third-party advisory
- drive.google.com