CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,746 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 1 of 35
- CVE-2025-48384CRITICALCVSS 8.0EG 9.0⚠ KEV2025-07-08
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and…
- CVE-2026-81963CRITICALCVSS 7.8EG 9.0⚠ KEV2026-09-08
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
- CVE-2026-41091CRITICALCVSS 7.8EG 9.0⚠ KEV2026-05-20
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
- CVE-2025-60710CRITICALCVSS 7.8EG 9.0⚠ KEV2025-11-11
Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.
- CVE-2023-36874CRITICALCVSS 7.8EG 9.0⚠ KEV2023-07-11
Windows Error Reporting Service Elevation of Privilege Vulnerability
- CVE-2022-21999CRITICALCVSS 7.8EG 9.0⚠ KEV2022-02-09
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2021-41379CRITICALCVSS 7.8EG 9.0⚠ KEV2021-11-10
Windows Installer Elevation of Privilege Vulnerability
- CVE-2020-3950CRITICALCVSS 7.8EG 9.0⚠ KEV2020-03-17
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. S…
- CVE-2020-0787CRITICALCVSS 7.8EG 9.0⚠ KEV2020-03-12
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
- CVE-2020-0683CRITICALCVSS 7.8EG 9.0⚠ KEV2020-02-11
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686.
- CVE-2020-0638CRITICALCVSS 7.8EG 9.0⚠ KEV2020-01-14
An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager El…
- CVE-2019-1385CRITICALCVSS 7.8EG 9.0⚠ KEV2019-11-12
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to…
- CVE-2019-1315CRITICALCVSS 7.8EG 9.0⚠ KEV2019-10-10
An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1339, CVE-20…
- CVE-2019-1253CRITICALCVSS 7.8EG 9.0⚠ KEV2019-09-11
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation …
- CVE-2019-1130CRITICALCVSS 7.8EG 9.0⚠ KEV2019-07-15
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129.
- CVE-2019-1129CRITICALCVSS 7.8EG 9.0⚠ KEV2019-07-15
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1130.
- CVE-2019-1069CRITICALCVSS 7.8EG 9.0⚠ KEV2019-06-12
An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploit …
- CVE-2019-1064CRITICALCVSS 7.8EG 9.0⚠ KEV2019-06-12
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker …
- CVE-2019-0841CRITICALCVSS 7.8EG 9.0⚠ KEV2019-04-09
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2…
- CVE-2015-5287CRITICALCVSS 7.8EG 9.0⚠ KEV2015-12-07
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abr…
- CVE-2015-1130CRITICALCVSS 7.8EG 9.0⚠ KEV2015-04-10
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.
- CVE-2022-30333CRITICALCVSS 7.5EG 9.0⚠ KEV2022-05-09
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.
- CVE-2020-36193CRITICALCVSS 7.5EG 9.0⚠ KEV2021-01-18
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.
- CVE-2024-57728CRITICALCVSS 7.2EG 9.0⚠ KEV2025-01-15
SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in t…
- CVE-2025-21391CRITICALCVSS 7.1EG 9.0⚠ KEV2025-02-11
Windows Storage Elevation of Privilege Vulnerability
- CVE-2022-21919CRITICALCVSS 7.0EG 9.0⚠ KEV2022-01-11
Windows User Profile Service Elevation of Privilege Vulnerability
- CVE-2026-34078CRITICALCVSS 10.0EG 10.02026-04-07
Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the …
- CVE-2024-37143CRITICALCVSS 10.0EG 10.02024-12-10
Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Ma…
- CVE-2024-28189CRITICALCVSS 10.0EG 10.02024-04-18
Judge0 is an open-source online code execution system. The application uses the UNIX chown command on an untrusted file within the sandbox. An attacker can abuse this by creating a symbolic link (symlink) to a file outside the sandbox, all…
- CVE-2024-28185CRITICALCVSS 10.0EG 10.02024-04-18
Judge0 is an open-source online code execution system. The application does not account for symlinks placed inside the sandbox directory, which can be leveraged by an attacker to write to arbitrary files and gain code execution outside of …
- CVE-2022-22995CRITICALCVSS 10.0EG 10.02022-03-25
The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.
- CVE-2014-4480HIGHCVSS v2 10.0EG 10.02015-01-30
Directory traversal vulnerability in afc in AppleFileConduit in Apple iOS before 8.1.3 and Apple TV before 7.0.3 allows attackers to access unintended filesystem locations by creating a symlink.
- CVE-2002-2374HIGHCVSS v2 10.0EG 10.02002-12-31
Unspecified vulnerability in pprosetup in Sun PatchPro 2.0 has unknown impact and attack vectors related to "unsafe use of temporary files."
- CVE-2026-87799CRITICALCVSS 9.9EG 9.92026-09-28
Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a proj…
- CVE-2026-100716CRITICALCVSS 9.9EG 9.92026-09-26
Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\FileDir::makeCorrectDir() contains an off-…
- CVE-2026-63125CRITICALCVSS 9.9EG 9.92026-08-21
Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code as…
- CVE-2026-63293CRITICALCVSS 9.9EG 9.92026-08-12
A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is a symbol…
- CVE-2026-63294CRITICALCVSS 9.9EG 9.92026-08-12
A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml f…
- CVE-2026-44881CRITICALCVSS 9.9EG 9.92026-05-28
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer su…
- CVE-2026-7374CRITICALCVSS 9.9EG 9.92026-05-26
A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console …
- CVE-2018-5225CRITICALCVSS 9.9EG 9.92018-03-22
In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (the fixed version for 5.5.x), 5.6.0 before 5.6.5 (the fixed version for 5.6.x), 5.7.0 befor…
- CVE-2026-82331CRITICALCVSS 9.8EG 9.82026-09-23
Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python < 3.12 allows malicious source tarballs to write files on the host, with the privileges of the …
- CVE-2026-50549CRITICALCVSS 9.8EG 9.82026-06-25
Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default. Before a Write, the agent canonicalizes the target path to confirm it stays inside the workspace, but when ca…
- CVE-2025-66277CRITICALCVSS 9.8EG 9.82026-02-11
A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to traverse the file system to unintended locations. We have already fixed the vuln…
- CVE-2025-43220CRITICALCVSS 9.8EG 9.82025-07-30
This issue was addressed with improved validation of symlinks. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access protected user data.
- CVE-2025-30457CRITICALCVSS 9.8EG 9.82025-03-31
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to create symlinks to protected regions of the disk.
- CVE-2024-48862CRITICALCVSS 9.8EG 9.82024-11-22
A link following vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers to traverse the file system to unintended locations and read or overwrite the contents of unexpected file…
- CVE-2024-6868CRITICALCVSS 9.8EG 9.82024-10-29
mudler/LocalAI version 2.17.1 allows for arbitrary file write due to improper handling of automatic archive extraction. When model configurations specify additional files as archives (e.g., .tar), these archives are automatically extracted…
- CVE-2023-36903CRITICALCVSS 9.8EG 9.82023-08-08
Windows System Assessment Tool Elevation of Privilege Vulnerability
- CVE-2021-3942CRITICALCVSS 9.8EG 9.82022-12-12
Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of Link-Local Multicast Name Resolution or LLMNR.
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →