CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,746 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 15 of 35
- CVE-2025-55247HIGHCVSS 7.3EG 7.32025-10-14
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.
- CVE-2025-8612HIGHCVSS 7.3EG 7.32025-08-20
AOMEI Backupper Workstation Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of AOMEI Backupper Workstation. An attacker must first obtain t…
- CVE-2025-5296HIGHCVSS 7.3EG 7.32025-08-18
CWE-59: Improper Link Resolution Before File Access ('Link Following') vulnerability exists that could cause arbitrary data to be written to protected locations, potentially leading to escalation of privilege, arbitrary file corruption, …
- CVE-2025-36611HIGHCVSS 7.3EG 7.32025-07-30
Dell Encryption and Dell Security Management Server, versions prior to 11.11.0, contain an Improper Link Resolution Before File Access ('Link Following') Vulnerability. A local malicious user could potentially exploit this vulnerability, l…
- CVE-2025-49680HIGHCVSS 7.3EG 7.32025-07-08
Improper link resolution before file access ('link following') in Windows Performance Recorder allows an authorized attacker to deny service locally.
- CVE-2025-53109HIGHCVSS 7.3EG 7.32025-07-02
Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versions of Filesystem prior to 0.6.4 or 2025.7.01 could allow access to unintended files via symlinks within allowed directo…
- CVE-2025-32721HIGHCVSS 7.3EG 7.32025-06-10
Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker to elevate privileges locally.
- CVE-2025-5474HIGHCVSS 7.3EG 7.32025-06-06
2BrightSparks SyncBackFree Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of 2BrightSparks SyncBackFree. An attacker must first obtain the…
- CVE-2025-4211HIGHCVSS 7.3EG 7.32025-05-16
Improper Link Resolution Before File Access ('Link Following') vulnerability in QFileSystemEngine in the Qt corelib module on Windows which potentially allows Symlink Attacks and the use of Malicious Files. Issue originates from CVE-2024-3…
- CVE-2025-21331HIGHCVSS 7.3EG 7.32025-01-14
Windows Installer Elevation of Privilege Vulnerability
- CVE-2024-12753HIGHCVSS 7.3EG 7.32024-12-30
Foxit PDF Reader Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute …
- CVE-2024-49107HIGHCVSS 7.3EG 7.32024-12-12
WmsRepair Service Elevation of Privilege Vulnerability
- CVE-2024-22038HIGHCVSS 7.3EG 7.32024-11-28
Various problems in obs-scm-bridge allows attackers that create specially crafted git repositories to leak information of cause denial of service.
- CVE-2024-51721HIGHCVSS 7.3EG 7.32024-11-12
A code injection vulnerability in the SecuSUITE Server Web Administration Portal of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially inject script commands or other executable content into the server that would…
- CVE-2024-43470HIGHCVSS 7.3EG 7.32024-09-10
Azure Network Watcher VM Agent Elevation of Privilege Vulnerability
- CVE-2024-38081HIGHCVSS 7.3EG 7.32024-07-09
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
- CVE-2024-30093HIGHCVSS 7.3EG 7.32024-06-11
Windows Storage Elevation of Privilege Vulnerability
- CVE-2024-26216HIGHCVSS 7.3EG 7.32024-04-09
Windows File Server Resource Management Service Elevation of Privilege Vulnerability
- CVE-2024-29007HIGHCVSS 7.3EG 7.32024-04-04
The CloudStack management server and secondary storage VM could be tricked into making requests to restricted or random resources by means of following 301 HTTP redirects presented by external servers when downloading templates or ISOs. Us…
- CVE-2023-41969HIGHCVSS 7.3EG 7.32024-03-26
An arbitrary file deletion in ZSATrayManager where it protects the temporary encrypted ZApp issue reporting file from the unprivileged end user access and modification. Fixed version: Win ZApp 4.3.0 and later.
- CVE-2024-21329HIGHCVSS 7.3EG 7.32024-02-13
Azure Connected Machine Agent Elevation of Privilege Vulnerability
- CVE-2023-35624HIGHCVSS 7.3EG 7.32023-12-12
Azure Connected Machine Agent Elevation of Privilege Vulnerability
- CVE-2022-38604HIGHCVSS 7.3EG 7.32023-04-11
Wacom Driver 6.3.46-1 for Windows and lower was discovered to contain an arbitrary file deletion vulnerability.
- CVE-2022-40143HIGHCVSS 7.3EG 7.32022-09-19
A link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service servers could allow a local attacker to abuse an insecure directory that could allow a low-privileged user to run arbit…
- CVE-2022-27883HIGHCVSS 7.3EG 7.32022-04-09
A link following vulnerability in Trend Micro Antivirus for Mac 11.5 could allow an attacker to create a specially-crafted file as a symlink that can lead to privilege escalation. Please note that an attacker must at least have low-level p…
- CVE-2021-32555HIGHCVSS 7.3EG 7.32021-06-12
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg-hwe-18.04 package apport hooks, it could expose private data to other local users.
- CVE-2021-32554HIGHCVSS 7.3EG 7.32021-06-12
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg package apport hooks, it could expose private data to other local users.
- CVE-2021-32553HIGHCVSS 7.3EG 7.32021-06-12
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-17 package apport hooks, it could expose private data to other local users.
- CVE-2021-32552HIGHCVSS 7.3EG 7.32021-06-12
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-16 package apport hooks, it could expose private data to other local users.
- CVE-2021-32551HIGHCVSS 7.3EG 7.32021-06-12
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-15 package apport hooks, it could expose private data to other local users.
- CVE-2021-32550HIGHCVSS 7.3EG 7.32021-06-12
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-14 package apport hooks, it could expose private data to other local users.
- CVE-2021-32549HIGHCVSS 7.3EG 7.32021-06-12
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-13 package apport hooks, it could expose private data to other local users.
- CVE-2021-32548HIGHCVSS 7.3EG 7.32021-06-12
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-8 package apport hooks, it could expose private data to other local users.
- CVE-2021-32547HIGHCVSS 7.3EG 7.32021-06-12
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-lts package apport hooks, it could expose private data to other local users.
- CVE-2019-1317HIGHCVSS 7.3EG 7.32019-10-10
A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'.
- CVE-2016-9595HIGHCVSS 7.3EG 7.32018-07-27
A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary …
- CVE-2025-32817HIGHCVSS 6.1EG 7.32025-04-16
A Improper Link Resolution vulnerability (CWE-59) in the SonicWall Connect Tunnel Windows (32 and 64 bit) client, this results in unauthorized file overwrite, potentially leading to denial of service or file corruption.
- CVE-2025-11578HIGHCVSS 7.2EG 7.22025-11-10
A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise admin to gain root SSH access to the appliance by exploiting a symlink escape in pre-receive hook environments. By cra…
- CVE-2025-23010HIGHCVSS 7.2EG 7.22025-04-10
An Improper Link Resolution Before File Access ('Link Following') vulnerability in SonicWall NetExtender Windows (32 and 64 bit) client which allows an attacker to manipulate file paths.
- CVE-2023-6336HIGHCVSS 7.2EG 7.22024-01-16
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows User-Controlled Filename.This issue affects Workforce Access: before 8.7.
- CVE-2020-8103HIGHCVSS 7.2EG 7.22020-06-05
A vulnerability in the improper handling of symbolic links in Bitdefender Antivirus Free can allow an unprivileged user to substitute a quarantined file, and restore it to a privileged location. This issue affects Bitdefender Antivirus Fre…
- CVE-2019-10152HIGHCVSS 7.2EG 7.22019-07-30
A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to b…
- CVE-2010-4226HIGHCVSS 7.2EG 7.22014-02-06
cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive.
- CVE-2024-14047HIGHCVSS 7.1EG 7.22026-09-01
A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users. A low-privileged attacker with existing access to the system could pre-position malicious filesystem…
- CVE-2022-20720HIGHCVSS 5.5EG 7.22022-04-15
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying …
- CVE-2008-5394HIGHCVSS v2 7.2EG 7.22008-12-09
/bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files via a symlink attack on a temporary file referenced in a line (aka ut_line) field …
- CVE-2008-4580HIGHCVSS v2 7.2EG 7.22008-10-15
fence_manual, as used in fence 2.02.00-r1 and possibly cman, allows local users to modify arbitrary files via a symlink attack on the fence_manual.fifo temporary file.
- CVE-2008-4553HIGHCVSS v2 7.2EG 7.22008-10-15
qemu-make-debian-root in qemu 0.9.1-5 on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on temporary files and directories.
- CVE-2008-4477HIGHCVSS v2 7.2EG 7.22008-10-08
alert.d/test.alert in mon 0.99.2 allows local users to overwrite arbitrary files via a symlink attack on the test.alert.log temporary file.
- CVE-2008-4475HIGHCVSS v2 7.2EG 7.22008-10-07
ibackup 2.27 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →