CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,746 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 8 of 35
- CVE-2024-43551HIGHCVSS 7.8EG 7.82024-10-08
Windows Storage Elevation of Privilege Vulnerability
- CVE-2024-43501HIGHCVSS 7.8EG 7.82024-10-08
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2024-8404HIGHCVSS 7.8EG 7.82024-09-26
An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting…
- CVE-2024-46744HIGHCVSS 7.8EG 7.82024-09-18
In the Linux kernel, the following vulnerability has been resolved: Squashfs: sanity check symbolic link size Syzkiller reports a "KMSAN: uninit-value in pick_link" bug. This is caused by an uninitialised page, which is ultimately cause…
- CVE-2024-5928HIGHCVSS 7.8EG 7.82024-08-21
VIPRE Advanced Security PMAgent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Advanced Security. An attacker must first obtain t…
- CVE-2024-38098HIGHCVSS 7.8EG 7.82024-08-13
Azure Connected Machine Agent Elevation of Privilege Vulnerability
- CVE-2024-38084HIGHCVSS 7.8EG 7.82024-08-13
Microsoft OfficePlus Elevation of Privilege Vulnerability
- CVE-2024-7252HIGHCVSS 7.8EG 7.82024-07-29
Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must fir…
- CVE-2024-7251HIGHCVSS 7.8EG 7.82024-07-29
Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must fir…
- CVE-2024-7250HIGHCVSS 7.8EG 7.82024-07-29
Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must fir…
- CVE-2024-7249HIGHCVSS 7.8EG 7.82024-07-29
Comodo Firewall Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Firewall. An attacker must first obtain the ability to execute lo…
- CVE-2024-35261HIGHCVSS 7.8EG 7.82024-07-09
Azure Network Watcher VM Extension Elevation of Privilege Vulnerability
- CVE-2024-6147HIGHCVSS 7.8EG 7.82024-06-20
Poly Plantronics Hub Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Poly Plantronics Hub. An attacker must first obtain the ability to …
- CVE-2024-30104HIGHCVSS 7.8EG 7.82024-06-11
Microsoft Office Remote Code Execution Vulnerability
- CVE-2024-36305HIGHCVSS 7.8EG 7.82024-06-10
A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code o…
- CVE-2024-4454HIGHCVSS 7.8EG 7.82024-05-22
WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of WithSecure Elements Endpoint Protection. User in…
- CVE-2023-51636HIGHCVSS 7.8EG 7.82024-05-22
Avira Prime Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avira Prime. An attacker must first obtain the ability to execute low-privil…
- CVE-2024-30060HIGHCVSS 7.8EG 7.82024-05-16
Azure Monitor Agent Elevation of Privilege Vulnerability
- CVE-2024-30018HIGHCVSS 7.8EG 7.82024-05-14
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2024-26238HIGHCVSS 7.8EG 7.82024-05-14
Microsoft PLUGScheduler Scheduled Task Elevation of Privilege Vulnerability
- CVE-2024-4712HIGHCVSS 7.8EG 7.82024-05-14
An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This specific flaw exists within the image-handler process, which can incorrectly create files that don’t exist …
- CVE-2024-3037HIGHCVSS 7.8EG 7.82024-05-14
An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting…
- CVE-2023-50226HIGHCVSS 7.8EG 7.82024-05-03
Parallels Desktop Updater Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability t…
- CVE-2023-50197HIGHCVSS 7.8EG 7.82024-05-03
Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Intel Driver & Support Assistant. An attacker must firs…
- CVE-2023-42126HIGHCVSS 7.8EG 7.82024-05-03
G DATA Total Security GDBackupSvc Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G Data Total Security. An attacker must first …
- CVE-2023-42125HIGHCVSS 7.8EG 7.82024-05-03
Avast Premium Security Sandbox Protection Link Following Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Premium Security. An attacker must first obtai…
- CVE-2023-42099HIGHCVSS 7.8EG 7.82024-05-03
Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Intel Driver & Support Assistant. An attacker must firs…
- CVE-2023-32179HIGHCVSS 7.8EG 7.82024-05-03
VIPRE Antivirus Plus FPQuarTransfer Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. An attacker must first obtain …
- CVE-2023-32178HIGHCVSS 7.8EG 7.82024-05-03
VIPRE Antivirus Plus TelFileTransfer Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. An attacker must first obtain…
- CVE-2023-32175HIGHCVSS 7.8EG 7.82024-05-03
VIPRE Antivirus Plus Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. An attacker must first obtain the ability to …
- CVE-2023-27347HIGHCVSS 7.8EG 7.82024-05-03
G DATA Total Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G Data Total Security. An attacker must first obtain the ability t…
- CVE-2024-28907HIGHCVSS 7.8EG 7.82024-04-09
Microsoft Brokering File System Elevation of Privilege Vulnerability
- CVE-2024-26158HIGHCVSS 7.8EG 7.82024-04-09
Microsoft Install Service Elevation of Privilege Vulnerability
- CVE-2024-21447HIGHCVSS 7.8EG 7.82024-04-09
Windows Authentication Elevation of Privilege Vulnerability
- CVE-2024-26199HIGHCVSS 7.8EG 7.82024-03-12
Microsoft Office Elevation of Privilege Vulnerability
- CVE-2023-42942HIGHCVSS 7.8EG 7.82024-02-21
This issue was addressed with improved handling of symlinks. This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, tvOS 17.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.1. A malicious app may be able to ga…
- CVE-2023-52338HIGHCVSS 7.8EG 7.82024-01-23
A link following vulnerability in the Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacke…
- CVE-2023-52094HIGHCVSS 7.8EG 7.82024-01-23
An updater link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to abuse the updater to delete an arbitrary folder, leading for a local privilege escalation on affected installations. Please note: …
- CVE-2023-52092HIGHCVSS 7.8EG 7.82024-01-23
A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code o…
- CVE-2023-52091HIGHCVSS 7.8EG 7.82024-01-23
An anti-spyware engine link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged …
- CVE-2023-52090HIGHCVSS 7.8EG 7.82024-01-23
A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code o…
- CVE-2023-47192HIGHCVSS 7.8EG 7.82024-01-23
An agent link vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code …
- CVE-2023-42137HIGHCVSS 7.8EG 7.82024-01-15
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privileges by using malicious symlinks. The attacker must have shell access to the device in order to …
- CVE-2024-20656HIGHCVSS 7.8EG 7.82024-01-09
Visual Studio Elevation of Privilege Vulnerability
- CVE-2024-0206HIGHCVSS 7.8EG 7.82024-01-09
A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to potentially gain an escalation of privileges. This was achieved by adding an entry to the re…
- CVE-2023-43116HIGHCVSS 7.8EG 7.82023-12-22
A symbolic link following vulnerability in Buildkite Elastic CI for AWS versions prior to 6.7.1 and 5.22.5 allows the buildkite-agent user to change ownership of arbitrary directories via the PIPELINE_PATH variable in the fix-buildkite-age…
- CVE-2023-36391HIGHCVSS 7.8EG 7.82023-12-12
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
- CVE-2023-35633HIGHCVSS 7.8EG 7.82023-12-12
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-43590HIGHCVSS 7.8EG 7.82023-11-15
Link following in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation of privilege via local access.
- CVE-2023-36705HIGHCVSS 7.8EG 7.82023-11-14
Windows Installer Elevation of Privilege Vulnerability
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →