CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,746 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 10 of 35
- CVE-2022-30523HIGHCVSS 7.8EG 7.82022-05-16
Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could allow a low privileged local attacker to delete the contents of an arbitrary folder as SYS…
- CVE-2022-23742HIGHCVSS 7.8EG 7.82022-05-12
Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious or linked content, such as exploiting C…
- CVE-2022-1256HIGHCVSS 7.8EG 7.82022-04-14
A local privilege escalation vulnerability in MA for Windows prior to 5.7.6 allows a local low privileged user to gain system privileges through running the repair functionality. Temporary file actions were performed on the local user's %T…
- CVE-2022-22962HIGHCVSS 7.8EG 7.82022-04-11
VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the default shared folder location due to a vulnerable symbolic link. Successful exploitation can result in linking to a root …
- CVE-2021-27117HIGHCVSS 7.8EG 7.82022-04-05
An issue was discovered in file profile.go in function GetCPUProfile in beego through 2.0.2, allows attackers to launch symlink attacks locally.
- CVE-2021-27116HIGHCVSS 7.8EG 7.82022-04-05
An issue was discovered in file profile.go in function MemProf in beego through 2.0.2, allows attackers to launch symlink attacks locally.
- CVE-2022-27815HIGHCVSS 7.8EG 7.82022-03-30
SWHKD 1.1.5 unsafely uses the /tmp/swhkd.pid pathname. There can be an information leak or denial of service.
- CVE-2022-24680HIGHCVSS 7.8EG 7.82022-02-24
A security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free Business Security 10.0 SP1 and Trend Micro Worry-Free Business Security Services agents c…
- CVE-2022-24679HIGHCVSS 7.8EG 7.82022-02-24
A security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free Business Security 10.0 SP1 and Trend Micro Worry-Free Business Security Services agents c…
- CVE-2022-24671HIGHCVSS 7.8EG 7.82022-02-24
A link following privilege escalation vulnerability in Trend Micro Antivirus for Max 11.0.2150 and below could allow a local attacker to modify a file during the update process and escalate their privileges. Please note: an attacker must f…
- CVE-2021-44730HIGHCVSS 7.8EG 7.82022-02-17
snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this binary to another location to cause snap-confine to execute other arbitrary binaries and hence gain privilege escalation…
- CVE-2022-21944HIGHCVSS 7.8EG 7.82022-01-26
A UNIX Symbolic Link (Symlink) Following vulnerability in the systemd service file for watchman of openSUSE Backports SLE-15-SP3, Factory allows local attackers to escalate to root. This issue affects: openSUSE Backports SLE-15-SP3 watchma…
- CVE-2022-21895HIGHCVSS 7.8EG 7.82022-01-11
Windows User Profile Service Elevation of Privilege Vulnerability
- CVE-2021-45231HIGHCVSS 7.8EG 7.82022-01-10
A link following privilege escalation vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to create a specially crafted file with arbitr…
- CVE-2021-43238HIGHCVSS 7.8EG 7.82021-12-15
Windows Remote Access Elevation of Privilege Vulnerability
- CVE-2021-43237HIGHCVSS 7.8EG 7.82021-12-15
Windows Setup Elevation of Privilege Vulnerability
- CVE-2021-42297HIGHCVSS 7.8EG 7.82021-11-24
Windows 10 Update Assistant Elevation of Privilege Vulnerability
- CVE-2021-44038HIGHCVSS 7.8EG 7.82021-11-19
An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to escalate their privileges to root upon package installation…
- CVE-2021-37969HIGHCVSS 7.8EG 7.82021-10-08
Inappropriate implementation in Google Updater in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to perform local privilege escalation via a crafted file.
- CVE-2021-34408HIGHCVSS 7.8EG 7.82021-09-27
The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable directory as a privileged user during the installation or update of the client. This could allow for potential privilege esca…
- CVE-2021-36744HIGHCVSS 7.8EG 7.82021-09-06
Trend Micro Security (Consumer) 2021 and 2020 are vulnerable to a directory junction vulnerability which could allow an attacker to exploit the system to escalate privileges and create a denial of service.
- CVE-2021-36928HIGHCVSS 7.8EG 7.82021-08-26
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- CVE-2021-26426HIGHCVSS 7.8EG 7.82021-08-12
Windows User Account Profile Picture Elevation of Privilege Vulnerability
- CVE-2021-26425HIGHCVSS 7.8EG 7.82021-08-12
Windows Event Tracing Elevation of Privilege Vulnerability
- CVE-2021-36983HIGHCVSS 7.8EG 7.82021-07-30
replay-sorcery-kms in Replay Sorcery 0.6.0 allows a local attacker to gain root privileges via a symlink attack on /tmp/replay-sorcery or /tmp/replay-sorcery/device.sock.
- CVE-2021-25321HIGHCVSS 7.8EG 7.82021-06-30
A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Factory, Leap 15.2 allows local attackers with control of the…
- CVE-2021-0094HIGHCVSS 7.8EG 7.82021-06-09
Improper link resolution before file access in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable an escalation of privilege via local access.
- CVE-2020-15076HIGHCVSS 7.8EG 7.82021-05-26
Private Tunnel installer for macOS version 3.0.1 and older versions may corrupt system critical files it should not have access via symlinks in /tmp.
- CVE-2020-9452HIGHCVSS 7.8EG 7.82021-05-25
An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe includes functionality to quarantine files by copying a suspected ransomware file from one directory to another using SYSTEM privileges. Because unp…
- CVE-2021-23872HIGHCVSS 7.8EG 7.82021-05-12
Privilege Escalation vulnerability in the File Lock component of McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated privileges by manipulating a symbolic link in the IOCTL interface.
- CVE-2021-31187HIGHCVSS 7.8EG 7.82021-05-11
Windows WalletService Elevation of Privilege Vulnerability
- CVE-2020-28007HIGHCVSS 7.8EG 7.82021-05-06
Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the log directory (owned by a non-root user), a symlink or hard link attack allows overwriting critical root-owned files anywhere on the fi…
- CVE-2021-28098HIGHCVSS 7.8EG 7.82021-04-14
An issue was discovered in Forescout CounterACT before 8.1.4. A local privilege escalation vulnerability is present in the logging function. SecureConnector runs with administrative privileges and writes logs entries to a file in %PROGRAMD…
- CVE-2021-28321HIGHCVSS 7.8EG 7.82021-04-13
Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability
- CVE-2021-30463HIGHCVSS 7.8EG 7.82021-04-08
VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. After reading the RKEY value from user.conf under the /usr/local/vesta/data/users/admin directory, the admin passwo…
- CVE-2020-7346HIGHCVSS 7.8EG 7.82021-03-23
Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) for Windows prior to 11.6.100 allows a local, low privileged, attacker through the use of junctions to cause the product to load DLLs of the attacker's choosing. This …
- CVE-2021-26889HIGHCVSS 7.8EG 7.82021-03-11
Windows Update Stack Elevation of Privilege Vulnerability
- CVE-2021-26887HIGHCVSS 7.8EG 7.82021-03-11
An elevation of privilege vulnerability exists in Microsoft Windows when Folder redirection has been enabled via Group Policy. When folder redirection file server is co-located with Terminal server, an attacker who successfully exploited t…
- CVE-2021-26873HIGHCVSS 7.8EG 7.82021-03-11
Windows User Profile Service Elevation of Privilege Vulnerability
- CVE-2021-26862HIGHCVSS 7.8EG 7.82021-03-11
Windows Installer Elevation of Privilege Vulnerability
- CVE-2021-3310HIGHCVSS 7.8EG 7.82021-03-10
Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead to code execution and information disclosure (by reading local files).
- CVE-2020-12878HIGHCVSS 7.8EG 7.82021-02-18
Digi ConnectPort X2e before 3.2.30.6 allows an attacker to escalate privileges from the python user to root via a symlink attack that uses chown, related to /etc/init.d/S50dropbear.sh and the /WEB/python/.ssh directory.
- CVE-2021-26720HIGHCVSS 7.8EG 7.82021-02-17
avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on…
- CVE-2021-23873HIGHCVSS 7.8EG 7.82021-02-10
Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and perform arbitrary file deletion as the SYSTEM user potentially causing Denial of Service via manipulat…
- CVE-2021-21117HIGHCVSS 7.8EG 7.82021-02-09
Insufficient policy enforcement in Cryptohome in Google Chrome prior to 88.0.4324.96 allowed a local attacker to perform OS-level privilege escalation via a crafted file.
- CVE-2021-23240HIGHCVSS 7.8EG 7.82021-01-12
selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC s…
- CVE-2020-35766HIGHCVSS 7.8EG 7.82020-12-28
The test suite in libopendkim in OpenDKIM through 2.10.3 allows local users to gain privileges via a symlink attack against the /tmp/testkeys file (related to t-testdata.h, t-setup.c, and t-cleanup.c). NOTE: this is applicable to persons w…
- CVE-2020-10003HIGHCVSS 7.8EG 7.82020-12-08
An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. A local attacker may b…
- CVE-2020-25989HIGHCVSS 7.8EG 7.82020-11-19
Privilege escalation via arbitrary file write in pritunl electron client 1.0.1116.6 through v1.2.2550.20. Successful exploitation of the issue may allow an attacker to execute code on the effected system with root privileges.
- CVE-2020-27697HIGHCVSS 7.8EG 7.82020-11-18
Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a malicious DLL in a non-protected location with high privileges (symlink attack) which can lead to obtaining adminis…
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →