CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,746 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 7 of 35
- CVE-2025-36564HIGHCVSS 7.8EG 7.82025-06-03
Dell Encryption Admin Utilities versions prior to 11.10.2 contain an Improper Link Resolution vulnerability. A local malicious user could potentially exploit this vulnerability, leading to privilege escalation.
- CVE-2024-54189HIGHCVSS 7.8EG 7.82025-06-03
A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is taken, a root service writes to a file owned by a normal user. By …
- CVE-2024-52561HIGHCVSS 7.8EG 7.82025-06-03
A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is deleted, a root service verifies and modifies the ownership of the…
- CVE-2024-36486HIGHCVSS 7.8EG 7.82025-06-03
A privilege escalation vulnerability exists in the virtual machine archive restoration functionality of Parallels Desktop for Mac version 20.1.1 (55740). When an archived virtual machine is restored, the prl_vmarchiver tool decompresses th…
- CVE-2024-11857HIGHCVSS 7.8EG 7.82025-06-02
Bluetooth HCI Adaptor from Realtek has a Link Following vulnerability. Local attackers with regular privileges can create a symbolic link with the same name as a specific file, causing the product to delete arbitrary files pointed to by th…
- CVE-2025-29975HIGHCVSS 7.8EG 7.82025-05-13
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
- CVE-2025-1079HIGHCVSS 7.8EG 7.82025-05-12
Client RCE on macOS and Linux via improper symbolic link resolution in Google Web Designer's preview feature
- CVE-2024-9524HIGHCVSS 7.8EG 7.82025-05-09
Link Following Local Privilege Escalation Vulnerability in System Speedup Service in Avira Operations GmbH Avira Prime Version 1.1.96.2 on Windows 10 x64 allows local attackers to escalate privileges and execute arbitrary code in the conte…
- CVE-2024-13962HIGHCVSS 7.8EG 7.82025-05-09
Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Gen Digital Inc. Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the c…
- CVE-2024-13961HIGHCVSS 7.8EG 7.82025-05-09
Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM …
- CVE-2024-13960HIGHCVSS 7.8EG 7.82025-05-09
Link Following Local Privilege Escalation Vulnerability in TuneUp Service in AVG TuneUp Version 23.4 (build 15592) on Windows 10 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating…
- CVE-2024-13959HIGHCVSS 7.8EG 7.82025-05-09
Link Following Local Privilege Escalation Vulnerability in TuneupSvc.exe in AVG TuneUp 24.2.16593.9844 on Windows allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic lin…
- CVE-2024-13944HIGHCVSS 7.8EG 7.82025-05-09
Link Following Local Privilege Escalation Vulnerability in NortonUtilitiesSvc in Norton Utilities Ultimate Version 24.2.16862.6344 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the contex…
- CVE-2024-13759HIGHCVSS 7.8EG 7.82025-05-09
Local Privilege Escalation in Avira.Spotlight.Service.exe in Avira Prime 1.1.96.2 on Windows 10 x64 allows local attackers to gain system-level privileges via arbitrary file deletion
- CVE-2025-3224HIGHCVSS 7.8EG 7.82025-04-28
A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-privileged attacker to escalate privileges to SYSTEM. During an update, Docker Desktop attempts to delete files and subd…
- CVE-2025-1697HIGHCVSS 7.8EG 7.82025-04-18
A potential security vulnerability has been identified in the HP Touchpoint Analytics Service for certain HP PC products with versions prior to 4.2.2439. This vulnerability could potentially allow a local attacker to escalate privileges. H…
- CVE-2025-27727HIGHCVSS 7.8EG 7.82025-04-08
Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.
- CVE-2025-21204HIGHCVSS 7.8EG 7.82025-04-08
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
- CVE-2025-29795HIGHCVSS 7.8EG 7.82025-03-23
Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.
- CVE-2025-1683HIGHCVSS 7.8EG 7.82025-03-12
Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivileged access on a Windows system to delete arbitrary files on the device by exploiting symbo…
- CVE-2025-21420HIGHCVSS 7.8EG 7.82025-02-11
Windows Disk Cleanup Tool Elevation of Privilege Vulnerability
- CVE-2025-21373HIGHCVSS 7.8EG 7.82025-02-11
Windows Installer Elevation of Privilege Vulnerability
- CVE-2025-21322HIGHCVSS 7.8EG 7.82025-02-11
Microsoft PC Manager Elevation of Privilege Vulnerability
- CVE-2025-0413HIGHCVSS 7.8EG 7.82025-02-05
Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obt…
- CVE-2024-52050HIGHCVSS 7.8EG 7.82024-12-31
A LogServer arbitrary file creation vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged co…
- CVE-2024-13043HIGHCVSS 7.8EG 7.82024-12-30
Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to ex…
- CVE-2024-47480HIGHCVSS 7.8EG 7.82024-12-18
Dell Inventory Collector Client, versions prior to 12.7.0, contains an Improper Link Resolution Before File Access vulnerability. A low-privilege attacker with local access may exploit this vulnerability, potentially resulting in Elevation…
- CVE-2024-12552HIGHCVSS 7.8EG 7.82024-12-13
Wacom Center WTabletServicePro Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Wacom Center. An attacker must first obtain the ability t…
- CVE-2024-7243HIGHCVSS 7.8EG 7.82024-11-22
Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to ex…
- CVE-2024-7242HIGHCVSS 7.8EG 7.82024-11-22
Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to ex…
- CVE-2024-7241HIGHCVSS 7.8EG 7.82024-11-22
Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to ex…
- CVE-2024-7240HIGHCVSS 7.8EG 7.82024-11-22
F-Secure Total Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of F-Secure Total. User interaction on the part of an administrator is requi…
- CVE-2024-7239HIGHCVSS 7.8EG 7.82024-11-22
VIPRE Advanced Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Advanced Security. An attacker must first obtain the abili…
- CVE-2024-7238HIGHCVSS 7.8EG 7.82024-11-22
VIPRE Advanced Security SBAMSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Advanced Security. An attacker must first obtain t…
- CVE-2024-7237HIGHCVSS 7.8EG 7.82024-11-22
AVG AntiVirus Free AVGSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of AVG AntiVirus Free. An attacker must first obtain the ability …
- CVE-2024-7234HIGHCVSS 7.8EG 7.82024-11-22
AVG AntiVirus Free AVGSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of AVG AntiVirus Free. An attacker must first obtain the ability …
- CVE-2024-7233HIGHCVSS 7.8EG 7.82024-11-22
Avast Free Antivirus AvastSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Free Antivirus. An attacker must first obtain the ab…
- CVE-2024-7232HIGHCVSS 7.8EG 7.82024-11-22
Avast Free Antivirus AvastSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Free Antivirus. An attacker must first obtain the ab…
- CVE-2024-7231HIGHCVSS 7.8EG 7.82024-11-22
Avast Cleanup Premium Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Cleanup Premium. An attacker must first obtain the ability t…
- CVE-2024-7230HIGHCVSS 7.8EG 7.82024-11-22
Avast Cleanup Premium Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Cleanup Premium. An attacker must first obtain the ability t…
- CVE-2024-7229HIGHCVSS 7.8EG 7.82024-11-22
Avast Cleanup Premium Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Cleanup Premium. An attacker must first obtain the ability t…
- CVE-2024-7227HIGHCVSS 7.8EG 7.82024-11-22
Avast Free Antivirus AvastSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Free Antivirus. An attacker must first obtain the ab…
- CVE-2024-9766HIGHCVSS 7.8EG 7.82024-11-22
Wacom Center WTabletServicePro Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Wacom Center. An attacker must first obtain the ability t…
- CVE-2024-6260HIGHCVSS 7.8EG 7.82024-11-22
Malwarebytes Antimalware Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Malwarebytes Antimalware. An attacker must first obtain the abi…
- CVE-2024-6233HIGHCVSS 7.8EG 7.82024-11-22
Check Point ZoneAlarm Extreme Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Check Point ZoneAlarm Extreme Security. An attack…
- CVE-2024-30377HIGHCVSS 7.8EG 7.82024-11-22
G DATA Total Security Scan Server Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total Security. An attacker must first obtain t…
- CVE-2024-1868HIGHCVSS 7.8EG 7.82024-11-22
G DATA Total Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total Security. An attacker must first obtain the ability t…
- CVE-2024-1867HIGHCVSS 7.8EG 7.82024-11-22
G DATA Total Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total Security. An attacker must first obtain the ability t…
- CVE-2024-49051HIGHCVSS 7.8EG 7.82024-11-12
Microsoft PC Manager Elevation of Privilege Vulnerability
- CVE-2024-45316HIGHCVSS 7.8EG 7.82024-10-11
The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard privileges to delete arbitrary folders and files, po…
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →