CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,746 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 6 of 35
- CVE-2026-62812HIGHCVSS 7.8EG 7.82026-08-11
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
- CVE-2026-63622HIGHCVSS 7.8EG 7.82026-08-10
A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtp…
- CVE-2026-12410HIGHCVSS 7.8EG 7.82026-08-05
Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-privileged attacker to escalate privileges to SYSTEM via a symlink/junction created during application uninstallation, …
- CVE-2026-40717HIGHCVSS 7.8EG 7.82026-08-03
Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation …
- CVE-2026-13268HIGHCVSS 7.8EG 7.82026-07-29
G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total Security. An attacker must first obtai…
- CVE-2026-50469HIGHCVSS 7.8EG 7.82026-07-14
Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.
- CVE-2026-49791HIGHCVSS 7.8EG 7.82026-07-14
Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-58636HIGHCVSS 7.8EG 7.82026-07-14
Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally.
- CVE-2026-49176HIGHCVSS 7.8EG 7.82026-07-14
Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.
- CVE-2026-41121HIGHCVSS 7.8EG 7.82026-07-01
Dell Device Management Agent, versions prior to DDMA 26.05, contain an Improper Link Resolution Before File Access ('Link Following’) vulnerability. A low privileged attacker with local access could potentially exploit this vulnerabilit…
- CVE-2026-11940HIGHCVSS 7.8EG 7.82026-06-23
tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself. The extraction fallback validated the symlink at it's …
- CVE-2026-44274HIGHCVSS 7.8EG 7.82026-06-22
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Before File Access vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauth…
- CVE-2026-54230HIGHCVSS 7.8EG 7.82026-06-13
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, t…
- CVE-2026-50511HIGHCVSS 7.8EG 7.82026-06-09
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
- CVE-2026-42989HIGHCVSS 7.8EG 7.82026-06-09
Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.
- CVE-2026-45586HIGHCVSS 7.8EG 7.82026-06-09
Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally.
- CVE-2025-71212HIGHCVSS 7.8EG 7.82026-05-21
A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code …
- CVE-2026-42834HIGHCVSS 7.8EG 7.82026-05-20
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
- CVE-2026-44471HIGHCVSS 7.8EG 7.82026-05-13
gitoxide is an implementation of git written in Rust. Prior to 0.21.1, a malicious tree can be constructed that will, when checked out with gitoxide, permit writing an attacker-controlled symlink into any existing directory the user has wr…
- CVE-2026-44470HIGHCVSS 7.8EG 7.82026-05-13
The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. Prior to 1.3834.0, the CoworkVMService component in Claude Desktop for Windows ran as SYSTEM and did not validate whe…
- CVE-2026-33694HIGHCVSS 7.8EG 7.82026-04-23
This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. As a result, this condition potentially facilitates arbitrary code execution, whereby an attacker may exploit the …
- CVE-2026-31979HIGHCVSS 7.8EG 7.82026-03-11
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Prior to 3.1.0 and 2.3.8, the himmelblaud-tasks daemon, running as root, writes Kerberos cache files under /tmp/krb5cc_<uid> without symlink protections. Sinc…
- CVE-2026-25187HIGHCVSS 7.8EG 7.82026-03-10
Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.
- CVE-2026-27905HIGHCVSS 7.8EG 7.82026-03-03
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.36, the safe_extract_tarfile() function validates that each tar member's path is within the destination directory, but …
- CVE-2026-25906HIGHCVSS 7.8EG 7.82026-03-03
Dell Optimizer, versions prior to 6.3.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevatio…
- CVE-2026-2627HIGHCVSS 7.8EG 7.82026-02-17
A security flaw has been discovered in Softland FBackup up to 9.9. This impacts an unknown function in the library C:\Program Files\Common Files\microsoft shared\ink\HID.dll of the component Backup/Restore. The manipulation results in link…
- CVE-2026-20610HIGHCVSS 7.8EG 7.82026-02-11
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Tahoe 26.3. An app may be able to gain root privileges.
- CVE-2025-15310HIGHCVSS 7.8EG 7.82026-02-10
Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.
- CVE-2025-15319HIGHCVSS 7.8EG 7.82026-02-09
Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.
- CVE-2026-24884HIGHCVSS 7.8EG 7.82026-02-04
Compressing is a compressing and uncompressing lib for node. In version 2.0.0 and 1.10.3 and prior, Compressing extracts TAR archives while restoring symbolic links without validating their targets. By embedding symlinks that resolve outsi…
- CVE-2026-20941HIGHCVSS 7.8EG 7.82026-01-13
Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.
- CVE-2025-7073HIGHCVSS 7.8EG 7.82025-12-10
A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privileged attackers to elevate privileges. The issue arises from bdservicehost.exe deleting files from a user-writable dir…
- CVE-2025-9871HIGHCVSS 7.8EG 7.82025-10-29
Razer Synapse 3 Chroma Connect Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Razer Synapse 3. An attacker must first obtain the abilit…
- CVE-2025-9870HIGHCVSS 7.8EG 7.82025-10-29
Razer Synapse 3 RazerPhilipsHueUninstall Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Razer Synapse 3. An attacker must first obtain …
- CVE-2025-9869HIGHCVSS 7.8EG 7.82025-10-29
Razer Synapse 3 Macro Module Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Razer Synapse 3. An attacker must first obtain the ability …
- CVE-2025-12341HIGHCVSS 7.8EG 7.82025-10-28
A vulnerability was detected in ermig1979 AntiDupl up to 2.3.12. Impacted is an unknown function of the file AntiDupl.NET.WinForms.exe of the component Delete Duplicate Image Handler. The manipulation results in link following. The attack …
- CVE-2025-59281HIGHCVSS 7.8EG 7.82025-10-14
Improper link resolution before file access ('link following') in XBox Gaming Services allows an authorized attacker to elevate privileges locally.
- CVE-2025-59241HIGHCVSS 7.8EG 7.82025-10-14
Improper link resolution before file access ('link following') in Windows Health and Optimized Experiences Service allows an authorized attacker to elevate privileges locally.
- CVE-2025-62363HIGHCVSS 7.8EG 7.82025-10-13
yt-grabber-tui is a terminal user interface application for downloading videos. In versions before 1.0-rc, the application allows users to configure the path to the yt-dlp executable via the path_to_yt_dlp configuration setting. An attacke…
- CVE-2025-11462HIGHCVSS 7.8EG 7.82025-10-07
Improper Link Resolution Before File Access in the AWS VPN Client for macOS versions 1.3.2- 5.2.0 allows a local user to execute code with elevated privileges. Insufficient validation checks on the log destination directory during log rota…
- CVE-2025-55317HIGHCVSS 7.8EG 7.82025-09-09
Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
- CVE-2025-55245HIGHCVSS 7.8EG 7.82025-09-09
Improper link resolution before file access ('link following') in Xbox allows an authorized attacker to elevate privileges locally.
- CVE-2025-52837HIGHCVSS 7.8EG 7.82025-07-10
Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could allow an attacker the opportunity to abuse symbolic links and other methods to delete any …
- CVE-2025-49738HIGHCVSS 7.8EG 7.82025-07-08
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
- CVE-2025-48820HIGHCVSS 7.8EG 7.82025-07-08
Improper link resolution before file access ('link following') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.
- CVE-2025-48799HIGHCVSS 7.8EG 7.82025-07-08
Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally.
- CVE-2025-30641HIGHCVSS 7.8EG 7.82025-06-17
A link following vulnerability in the anti-malware solution portion of Trend Micro Deep Security 20.0 agents could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the a…
- CVE-2025-30640HIGHCVSS 7.8EG 7.82025-06-17
A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code…
- CVE-2025-49157HIGHCVSS 7.8EG 7.82025-06-17
A link following vulnerability in the Trend Micro Apex One Damage Cleanup Engine could allow a local attacker to escalation privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-priv…
- CVE-2025-33075HIGHCVSS 7.8EG 7.82025-06-10
Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →