CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,749 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 18 of 35
- CVE-2021-32000HIGHCVSS 3.2EG 7.12021-07-28
A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up in SUSE Linux Enterprise Server 12 SP3, SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allows local attackers to …
- CVE-2026-92371HIGHCVSS 7.0EG 7.02026-09-29
TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file …
- CVE-2026-100419HIGHCVSS 7.0EG 7.02026-09-25
gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that allows attackers to escape the worktree directory via symlink manipulation. During forced checkout with overwrite_existin…
- CVE-2026-83999HIGHCVSS 7.0EG 7.02026-09-08
Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69379HIGHCVSS 7.0EG 7.02026-09-08
Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to elevate privileges locally.
- CVE-2026-78409HIGHCVSS 7.0EG 7.02026-09-02
The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution insi…
- CVE-2026-81726HIGHCVSS 7.0EG 7.02026-08-27
NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox roots thr…
- CVE-2026-66153HIGHCVSS 7.0EG 7.02026-08-25
The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to manipulate file paths.
- CVE-2026-15994HIGHCVSS 7.0EG 7.02026-08-13
During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to execute code with elevated privileges.
- CVE-2026-6851HIGHCVSS 7.0EG 7.02026-07-14
An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in Bitdefender Total Security and Internet Security on Windows allows a less-privileged local user to elevate rights by lev…
- CVE-2026-7832HIGHCVSS 7.0EG 7.02026-05-05
A security flaw has been discovered in IObit Advanced SystemCare 19. This affects an unknown part of the file ASC.exe of the component Service. The manipulation results in symlink following. Attacking locally is a requirement. This attack …
- CVE-2026-21517HIGHCVSS 7.0EG 7.02026-02-10
Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally.
- CVE-2025-11489HIGHCVSS 7.0EG 7.02025-10-08
A security vulnerability has been detected in wonderwhy-er DesktopCommanderMCP up to 0.2.13. This vulnerability affects the function isPathAllowed of the file src/tools/filesystem.ts. The manipulation leads to symlink following. The attack…
- CVE-2025-49156HIGHCVSS 7.0EG 7.02025-06-17
A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalation privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged cod…
- CVE-2025-22480HIGHCVSS 7.0EG 7.02025-02-13
Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary file deletion and Elevat…
- CVE-2024-49059HIGHCVSS 7.0EG 7.02024-12-12
Microsoft Office Elevation of Privilege Vulnerability
- CVE-2024-38022HIGHCVSS 7.0EG 7.02024-07-09
Windows Image Acquisition Elevation of Privilege Vulnerability
- CVE-2024-5102HIGHCVSS 7.0EG 7.02024-06-10
A sym-linked file accessed via the repair function in Avast Antivirus <24.2 on Windows may allow user to elevate privilege to delete arbitrary files or run processes as NT AUTHORITY\SYSTEM. The vulnerability exists within the "Repair" (se…
- CVE-2024-30033HIGHCVSS 7.0EG 7.02024-05-14
Windows Search Service Elevation of Privilege Vulnerability
- CVE-2024-21432HIGHCVSS 7.0EG 7.02024-03-12
Windows Update Stack Elevation of Privilege Vulnerability
- CVE-2023-36394HIGHCVSS 7.0EG 7.02023-11-14
Windows Search Service Elevation of Privilege Vulnerability
- CVE-2023-36568HIGHCVSS 7.0EG 7.02023-10-10
Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
- CVE-2023-32050HIGHCVSS 7.0EG 7.02023-07-11
Windows Installer Elevation of Privilege Vulnerability
- CVE-2023-0652HIGHCVSS 7.0EG 7.02023-04-06
Due to a hardlink created in the ProgramData folder during the repair process of the software, the installer (MSI) of WARP Client for Windows (<= 2022.12.582.0) allowed a malicious attacker to forge the destination of the hardlink and esca…
- CVE-2023-1412HIGHCVSS 7.0EG 7.02023-04-05
An unprivileged (non-admin) user can exploit an Improper Access Control vulnerability in the Cloudflare WARP Client for Windows (<= 2022.12.582.0) to perform privileged operations with SYSTEM context by working with a combination of opport…
- CVE-2023-21542HIGHCVSS 7.0EG 7.02023-01-10
Windows Installer Elevation of Privilege Vulnerability
- CVE-2009-1143HIGHCVSS 7.0EG 7.02022-11-23
An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended access restrictions on mounting shares via a symlink attack that leverages a realpath race condition in mount.vmhgfs (aka hgfsmounter).
- CVE-2022-0017HIGHCVSS 7.0EG 7.02022-02-10
An improper link resolution before file access ('link following') vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that enables a local attacker to disrupt system processes and potentially execute arbitrary code …
- CVE-2020-10174HIGHCVSS 7.0EG 7.02020-03-05
init_tmp in TeeJee.FileSystem.vala in Timeshift before 20.03 unsafely reuses a preexisting temporary directory in the predictable location /tmp/timeshift. It follows symlinks in this location or uses directories owned by unprivileged users…
- CVE-2019-18932HIGHCVSS 7.0EG 7.02020-01-21
log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By default, it uses a fixed temporary directory /tmp/sarg. As the root user, sarg creates this directory or reuses an existing one in an inse…
- CVE-2019-13226HIGHCVSS 7.0EG 7.02019-07-04
deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/<block-dev-basename> in the Helper::temporaryMountDevice() function to temporarily mount a file system as root. An unprivileged user can prepare a symlink at this l…
- CVE-2019-8454HIGHCVSS 7.0EG 7.02019-04-29
A local attacker can create a hard-link between a file to which the Check Point Endpoint Security client for Windows before E80.96 writes and another BAT file, then by impersonating the WPAD server, the attacker can write BAT commands into…
- CVE-2019-5674HIGHCVSS 7.0EG 7.02019-03-28
NVIDIA GeForce Experience before 3.18 contains a vulnerability when ShadowPlay or GameStream is enabled. When an attacker has access to the system and creates a hard link, the software does not check for hard link attacks. This behavior ma…
- CVE-2019-8372HIGHCVSS 7.0EG 7.02019-02-18
The LHA.sys driver before 1.1.1811.2101 in LG Device Manager exposes functionality that allows low-privileged users to read and write arbitrary physical memory via specially crafted IOCTL requests and elevate system privileges. This occurs…
- CVE-2018-6557HIGHCVSS 7.0EG 7.02018-08-21
The MOTD update script in the base-files package in Ubuntu 18.04 LTS before 10.1ubuntu2.2, and Ubuntu 18.10 before 10.1ubuntu6 incorrectly handled temporary files. A local attacker could use this issue to cause a denial of service, or poss…
- CVE-2016-6664HIGHCVSS 7.0EG 7.02016-12-13
mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6…
- CVE-2004-0217HIGHCVSS 7.0EG 7.02004-04-15
The LiveUpdate capability (liveupdate.sh) in Symantec AntiVirus Scan Engine 4.0 and 4.3 for Red Hat Linux allows local users to create or append to arbitrary files via a symlink attack on /tmp/LiveUpdate.log.
- CVE-2026-89021MEDIUMCVSS 6.9EG 6.92026-09-14
MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlinks …
- CVE-2014-3486MEDIUMCVSS v2 6.9EG 6.92014-07-07
The (1) shell_exec function in lib/util/MiqSshUtilV1.rb and (2) temp_cmd_file function in lib/util/MiqSshUtilV2.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allow local users to execute arbitrary commands via a syml…
- CVE-2014-3977MEDIUMCVSS v2 6.9EG 6.92014-06-08
libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-2179.
- CVE-2013-4169MEDIUMCVSS v2 6.9EG 6.92013-09-10
GNOME Display Manager (gdm) before 2.21.1 allows local users to change permissions of arbitrary directories via a symlink attack on /tmp/.X11-unix/.
- CVE-2013-1976MEDIUMCVSS v2 6.9EG 6.92013-07-09
The (1) tomcat5, (2) tomcat6, and (3) tomcat7 init scripts, as used in the RPM distribution of Tomcat for JBoss Enterprise Web Server 1.0.2 and 2.0.0, and Red Hat Enterprise Linux 5 and 6, allow local users to change the ownership of arbit…
- CVE-2013-1495MEDIUMCVSS v2 6.9EG 6.92013-03-18
asr in Oracle Auto Service Request in Oracle Support Tools before 4.3.2 allows local users to modify arbitrary files via a symlink attack on a predictable filename in /tmp.
- CVE-2013-1423MEDIUMCVSS v2 6.9EG 6.92013-03-14
(1) contrib/gforge-3.0-cronjobs.patch, (2) cronjobs/homedirs.php, (3) deb-specific/fileforge.pl, (4) deb-specific/group_dump_update.pl, (5) deb-specific/ssh_dump_update.pl, (6) deb-specific/user_dump_update.pl, (7) plugins/scmbzr/common/Bz…
- CVE-2012-5303MEDIUMCVSS v2 6.9EG 6.92012-10-05
Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink attack on a PID file, as demonstrated by a pathname different from the default /var/run/monkey.pid pathname.
- CVE-2011-0727MEDIUMCVSS v2 6.9EG 6.92011-03-31
GNOME Display Manager (gdm) 2.x before 2.32.1 allows local users to change the ownership of arbitrary files via a symlink attack on a (1) dmrc or (2) face icon file under /var/cache/gdm/.
- CVE-2010-3847MEDIUMCVSS v2 6.9EG 6.92011-01-07
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via …
- CVE-2010-0832MEDIUMCVSS v2 6.9EG 6.92010-07-12
pam_motd (aka the MOTD module) in libpam-modules before 1.1.0-2ubuntu1.1 in PAM on Ubuntu 9.10 and libpam-modules before 1.1.1-2ubuntu5 in PAM on Ubuntu 10.04 LTS allows local users to change the ownership of arbitrary files via a symlink …
- CVE-2010-0439MEDIUMCVSS v2 6.9EG 6.92010-03-26
Chip Salzenberg Deliver allows local users to cause a denial of service, obtain sensitive information, and possibly change the ownership of arbitrary files via a symlink attack on an unspecified file.
- CVE-2009-1299MEDIUMCVSS v2 6.9EG 6.92010-03-18
The pa_make_secure_dir function in core-util.c in PulseAudio 0.9.10 and 0.9.19 allows local users to change the ownership and permissions of arbitrary files via a symlink attack on a /tmp/.esd-##### temporary file.
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →