Microsoft AVML before 0.17.0 could follow a symlink when opening a destination output path on Unix, allowing truncation/overwrite of the symlink target. The destructive effect is performed at open-time via O_TRUNC, and can happen before full input validation completes (“truncation-before-validation”).

Project Subscriptions

Vendors Products
Microsoft Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 31 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Symlink Truncation Vulnerability in Microsoft AVML Prior to 0.17.0

Thu, 30 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft avml
Vendors & Products Microsoft
Microsoft avml

Tue, 28 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Symlink‑Based Truncation and Overwrite Vulnerability in Microsoft AVML

Sat, 25 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Symlink‑Based Truncation and Overwrite Vulnerability in Microsoft AVML

Wed, 22 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unix Symlink Truncation/Overwrite in Microsoft AVML Before 0.17.0

Fri, 17 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Unix Symlink Truncation/Overwrite in Microsoft AVML Before 0.17.0

Wed, 15 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-59
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Description Microsoft AVML before 0.17.0 could follow a symlink when opening a destination output path on Unix, allowing truncation/overwrite of the symlink target. The destructive effect is performed at open-time via O_TRUNC, and can happen before full input validation completes (“truncation-before-validation”).
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-15T19:26:26.306Z

Reserved: 2026-07-08T00:00:00.000Z

Link: CVE-2026-61371

cve-icon Vulnrichment

Updated: 2026-07-15T19:26:18.993Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-15T16:16:50.307

Modified: 2026-07-15T20:56:32.437

Link: CVE-2026-61371

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T04:15:04Z

Weaknesses