CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,746 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 17 of 35
- CVE-2023-36046HIGHCVSS 7.1EG 7.12023-11-14
Windows Authentication Denial of Service Vulnerability
- CVE-2020-28407HIGHCVSS 7.1EG 7.12023-11-03
In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.
- CVE-2023-36876HIGHCVSS 7.1EG 7.12023-08-08
Reliability Analysis Metrics Calculation (RacTask) Elevation of Privilege Vulnerability
- CVE-2023-35347HIGHCVSS 7.1EG 7.12023-07-11
Microsoft Install Service Elevation of Privilege Vulnerability
- CVE-2023-27469HIGHCVSS 7.1EG 7.12023-06-30
Malwarebytes Anti-Exploit 4.4.0.220 is vulnerable to arbitrary file deletion and denial of service via an ALPC message in which FullFileNamePath lacks a '\0' character.
- CVE-2023-24904HIGHCVSS 7.1EG 7.12023-05-09
Windows Installer Elevation of Privilege Vulnerability
- CVE-2022-34292HIGHCVSS 7.1EG 7.12023-04-27
Docker Desktop for Windows before 4.6.0 allows attackers to overwrite any file through a symlink attack on the hyperv/create dockerBackendV2 API by controlling the DataFolder parameter for DockerDesktop.vhdx, a similar issue to CVE-2022-31…
- CVE-2022-31647HIGHCVSS 7.1EG 7.12023-04-27
Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 API via a symlink in the DataFolder parameter, a different vulnerability than CVE-2022-26659.
- CVE-2023-28222HIGHCVSS 7.1EG 7.12023-04-11
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-21760HIGHCVSS 7.1EG 7.12023-01-10
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-32450HIGHCVSS 7.1EG 7.12022-07-18
AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder (used for ad.trace and chat) but the product runs as SYSTEM when writing chat-room data there.
- CVE-2022-30687HIGHCVSS 7.1EG 7.12022-05-27
Trend Micro Maximum Security 2022 is vulnerable to a link following vulnerability that could allow a low privileged local user to manipulate the product's secure erase feature to delete arbitrary files.
- CVE-2022-27816HIGHCVSS 7.1EG 7.12022-03-30
SWHKD 1.1.5 unsafely uses the /tmp/swhks.pid pathname. There can be data loss or a denial of service.
- CVE-2022-26659HIGHCVSS 7.1EG 7.12022-03-25
Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink in place of where the installer writes its log file. Starting from version 4.6.0, the Docke…
- CVE-2022-21997HIGHCVSS 7.1EG 7.12022-02-09
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2021-45442HIGHCVSS 7.1EG 7.12022-01-10
A link following denial-of-service vulnerability in Trend Micro Worry-Free Business Security (on prem only) could allow a local attacker to overwrite arbitrary files in the context of SYSTEM. This is similar to, but not the same as CVE-202…
- CVE-2021-44024HIGHCVSS 7.1EG 7.12022-01-10
A link following denial-of-service vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to overwrite arbitrary files in the context of SY…
- CVE-2021-44023HIGHCVSS 7.1EG 7.12021-12-16
A link following denial-of-service (DoS) vulnerability in the Trend Micro Security (Consumer) 2021 familiy of products could allow an attacker to abuse the PC Health Checkup feature of the product to create symlinks that would allow modifi…
- CVE-2021-41057HIGHCVSS 7.1EG 7.12021-11-14
In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.
- CVE-2021-36286HIGHCVSS 7.1EG 7.12021-09-28
Dell SupportAssist Client Consumer versions 3.9.13.0 and any versions prior to 3.9.13.0 contain an arbitrary file deletion vulnerability that can be exploited by using the Windows feature of NTFS called Symbolic links. Symbolic links can b…
- CVE-2021-1092HIGHCVSS 7.1EG 7.12021-07-22
NVIDIA GPU Display Driver for Windows contains a vulnerability in the NVIDIA Control Panel application where it is susceptible to a Windows file system symbolic link attack where an unprivileged attacker can cause the applications to overw…
- CVE-2021-1091HIGHCVSS 7.1EG 7.12021-07-22
NVIDIA GPU Display driver for Windows contains a vulnerability where an unprivileged user can create a file hard link that causes the driver to overwrite a file that requires elevated privilege to modify, which could lead to data loss or d…
- CVE-2020-27833HIGHCVSS 7.1EG 7.12021-05-14
A Zip Slip vulnerability was found in the oc binary in openshift-clients where an arbitrary file write is achieved by using a specially crafted raw container image (.tar file) which contains symbolic links. The vulnerability is limited to …
- CVE-2020-15075HIGHCVSS 7.1EG 7.12021-03-30
OpenVPN Connect installer for macOS version 3.2.6 and older may corrupt system critical files it should not have access via symlinks in /tmp.
- CVE-2020-28641HIGHCVSS 7.1EG 7.12020-12-22
In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system.
- CVE-2020-16853HIGHCVSS 7.1EG 7.12020-09-11
<p>An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevat…
- CVE-2020-16851HIGHCVSS 7.1EG 7.12020-09-11
<p>An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevat…
- CVE-2020-14990HIGHCVSS 7.1EG 7.12020-06-22
IOBit Advanced SystemCare Free 13.5.0.263 allows local users to gain privileges for file deletion by manipulating the Clean & Optimize feature with an NTFS junction and an Object Manager symbolic link.
- CVE-2020-8099HIGHCVSS 7.1EG 7.12020-04-21
A vulnerability in the improper handling of junctions in Bitdefender Antivirus Free can allow an unprivileged user to substitute a quarantined file, and restore it to a privileged location. This issue affects: Bitdefender Antivirus Free ve…
- CVE-2020-0789HIGHCVSS 7.1EG 7.12020-03-12
A denial of service vulnerability exists when the Visual Studio Extension Installer Service improperly handles hard links, aka 'Visual Studio Extension Installer Service Denial of Service Vulnerability'.
- CVE-2020-5324HIGHCVSS 7.1EG 7.12020-02-21
Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is limited to the Dell Firmware Update Utility during the time window while being executed by an administrator. During this …
- CVE-2020-0730HIGHCVSS 7.1EG 7.12020-02-11
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.
- CVE-2019-19693HIGHCVSS 7.1EG 7.12019-12-20
The Trend Micro Security 2020 consumer family of products contains a vulnerability that could allow a local attacker to disclose sensitive information or to create a denial-of-service condition on affected installations. An attacker must f…
- CVE-2019-18575HIGHCVSS 7.1EG 7.12019-12-06
Dell Command Configure versions prior to 4.2.1 contain an uncontrolled search path vulnerability. A locally authenticated malicious user could exploit this vulnerability by creating a symlink to a target file, allowing the attacker to over…
- CVE-2011-3632HIGHCVSS 7.1EG 7.12019-11-26
Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks.
- CVE-2011-3351HIGHCVSS 7.1EG 7.12019-11-25
openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating OVAL system characteristics document with the ovaldi integrated tool enabled. A local attacker could use this flaw to conduct symlink attacks to overwrit…
- CVE-2010-2064HIGHCVSS 7.1EG 7.12019-10-29
rpcbind 0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr.
- CVE-2019-15627HIGHCVSS 7.1EG 7.12019-10-17
Versions 10.0, 11.0 and 12.0 of the Trend Micro Deep Security Agent are vulnerable to an arbitrary file delete attack, which may lead to availability impact. Local OS access is required. Please note that only Windows agents are affected.
- CVE-2019-12573HIGHCVSS 7.1EG 7.12019-07-11
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attacker to overwrite arbitrary files. The openvpn_launcher binary is setuid root. This binary s…
- CVE-2019-12571HIGHCVSS 7.1EG 7.12019-07-11
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v0.9.8 beta (build 02099) for macOS could allow an authenticated, local attacker to overwrite arbitrary files. When the client initiates a connection, the X…
- CVE-2019-12749HIGHCVSS 7.1EG 7.12019-06-11
dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon), allows cookie spoofing because of symlink mishandling in the…
- CVE-2019-12779HIGHCVSS 7.1EG 7.12019-06-07
libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.
- CVE-2019-1836HIGHCVSS 7.1EG 7.12019-05-03
A vulnerability in the system shell for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to use symbolic links to overwrite system files. These system fil…
- CVE-2019-8455HIGHCVSS 7.1EG 7.12019-04-17
A hard-link created from the log file of Check Point ZoneAlarm up to 15.4.062 to any file on the system will get its permission changed so that all users can access that linked file. Doing this on files with limited access gains the local …
- CVE-2013-0159HIGHCVSS 7.1EG 7.12018-05-01
The fedora-business-cards package before 1-0.1.beta1.fc17 on Fedora 17 and before 1-0.1.beta1.fc18 on Fedora 18 allows local users to cause a denial of service or write to arbitrary files via a symlink attack on /tmp/fedora-business-cards-…
- CVE-2016-3108HIGHCVSS 7.1EG 7.12017-06-08
The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink attack.
- CVE-2004-0689HIGHCVSS 7.1EG 7.12004-09-28
KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.
- CVE-2003-0844HIGHCVSS 7.1EG 7.12003-11-17
mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a symlink attack on predictable temporary filenames on Unix sy…
- CVE-2019-0986HIGHCVSS 6.3EG 7.12019-06-12
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context. To…
- CVE-2023-20008HIGHCVSS 4.4EG 7.12023-01-20
A vulnerability in the CLI of Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to overwrite arbitrary files on the local system of an affected device. This vulnerability is due to improper access co…
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →