CWE-59— Improper Link Resolution Before File Access (Link Following)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.— MITRE CWE catalog
1,746 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-59page 9 of 35
- CVE-2023-36047HIGHCVSS 7.8EG 7.82023-11-14
Windows Authentication Elevation of Privilege Vulnerability
- CVE-2023-5834HIGHCVSS 7.8EG 7.82023-10-27
HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauthorized file system writes. Fixed in Vagrant 2.4.0.
- CVE-2023-36737HIGHCVSS 7.8EG 7.82023-10-10
Azure Network Watcher VM Agent Elevation of Privilege Vulnerability
- CVE-2023-36723HIGHCVSS 7.8EG 7.82023-10-10
Windows Container Manager Service Elevation of Privilege Vulnerability
- CVE-2023-36711HIGHCVSS 7.8EG 7.82023-10-10
Windows Runtime C++ Template Library Elevation of Privilege Vulnerability
- CVE-2023-36758HIGHCVSS 7.8EG 7.82023-09-12
Visual Studio Elevation of Privilege Vulnerability
- CVE-2023-32163HIGHCVSS 7.8EG 7.82023-09-06
Wacom Drivers for Windows Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Wacom Drivers for Windows. An attacker must first obtain the a…
- CVE-2022-46869HIGHCVSS 7.8EG 7.82023-08-31
Local privilege escalation during installation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40278, Acronis True Image OEM (Windows) before build 42575.
- CVE-2019-13689HIGHCVSS 7.8EG 7.82023-08-25
Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform arbitrary read/write via a malicious file. (Chromium security severity: Critical)
- CVE-2023-38175HIGHCVSS 7.8EG 7.82023-08-08
Microsoft Windows Defender Elevation of Privilege Vulnerability
- CVE-2023-35379HIGHCVSS 7.8EG 7.82023-08-08
Reliability Analysis Metrics Calculation Engine (RACEng) Elevation of Privilege Vulnerability
- CVE-2023-35353HIGHCVSS 7.8EG 7.82023-07-11
Connected User Experiences and Telemetry Elevation of Privilege Vulnerability
- CVE-2023-35342HIGHCVSS 7.8EG 7.82023-07-11
Windows Image Acquisition Elevation of Privilege Vulnerability
- CVE-2023-35320HIGHCVSS 7.8EG 7.82023-07-11
Connected User Experiences and Telemetry Elevation of Privilege Vulnerability
- CVE-2023-33148HIGHCVSS 7.8EG 7.82023-07-11
Microsoft Office Elevation of Privilege Vulnerability
- CVE-2023-32056HIGHCVSS 7.8EG 7.82023-07-11
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
- CVE-2023-32053HIGHCVSS 7.8EG 7.82023-07-11
Windows Installer Elevation of Privilege Vulnerability
- CVE-2023-32012HIGHCVSS 7.8EG 7.82023-06-14
Windows Container Manager Service Elevation of Privilege Vulnerability
- CVE-2023-33865HIGHCVSS 7.8EG 7.82023-06-07
RenderDoc before 1.27 allows local privilege escalation via a symlink attack. It relies on the /tmp/RenderDoc directory regardless of ownership.
- CVE-2023-2939HIGHCVSS 7.8EG 7.82023-05-30
Insufficient data validation in Installer in Google Chrome on Windows prior to 114.0.5735.90 allowed a local attacker to perform privilege escalation via crafted symbolic link. (Chromium security severity: Medium)
- CVE-2023-27529HIGHCVSS 7.8EG 7.82023-05-25
Wacom Tablet Driver installer prior to 6.4.2-1 (for macOS) contains an improper link resolution before file access vulnerability. When a user is tricked to execute a small malicious script before executing the affected version of the insta…
- CVE-2023-29343HIGHCVSS 7.8EG 7.82023-05-09
SysInternals Sysmon for Windows Elevation of Privilege Vulnerability
- CVE-2022-47505HIGHCVSS 7.8EG 7.82023-04-21
The SolarWinds Platform was susceptible to the Local Privilege Escalation Vulnerability. This vulnerability allows a local adversary with a valid system user account to escalate local privileges.
- CVE-2023-28892HIGHCVSS 7.8EG 7.82023-03-29
Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:\AdwCleaner\Logs\AdwCleaner_Debug.log in which the target location is user-controllable, allowing a non-admin user to escalate privileg…
- CVE-2023-26088HIGHCVSS 7.8EG 7.82023-03-23
In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the local quarantine system. It can also lead to privilege escalation in certain scenarios.
- CVE-2023-24930HIGHCVSS 7.8EG 7.82023-03-14
Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability
- CVE-2023-25148HIGHCVSS 7.8EG 7.82023-03-10
A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to exploit the vulnerability by changing a specific file into a pseudo-symlink, allowing privilege escalation on affected installations. …
- CVE-2023-25146HIGHCVSS 7.8EG 7.82023-03-10
A security agent link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to quarantine a file, delete the original folder and replace with a junction to an arbitrary location, ultimately leading to an ar…
- CVE-2023-25145HIGHCVSS 7.8EG 7.82023-03-10
A link following vulnerability in the scanning function of Trend Micro Apex One agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-p…
- CVE-2022-45697HIGHCVSS 7.8EG 7.82023-02-27
Arbitrary File Delete vulnerability in Razer Central before v7.8.0.381 when handling files in the Accounts directory.
- CVE-2020-36657HIGHCVSS 7.8EG 7.82023-01-26
uptimed before 0.4.6-r1 on Gentoo allows local users (with access to the uptimed user account) to gain root privileges by creating a hard link within the /var/spool/uptimed directory, because there is an unsafe chown -R call.
- CVE-2023-21678HIGHCVSS 7.8EG 7.82023-01-10
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-45798HIGHCVSS 7.8EG 7.82022-12-24
A link following vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One as a Service could allow a local attacker to escalate privileges by creating a symbolic link and abusing the service to …
- CVE-2022-4563HIGHCVSS 7.8EG 7.82022-12-16
A vulnerability was found in Freedom of the Press SecureDrop. It has been rated as critical. Affected by this issue is some unknown functionality of the file gpg-agent.conf. The manipulation leads to symlink following. Local access is requ…
- CVE-2022-44747HIGHCVSS 7.8EG 7.82022-11-07
Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107.
- CVE-2022-32905HIGHCVSS 7.8EG 7.82022-11-01
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13. Processing a maliciously crafted DMG file may lead to arbitrary code execution with system privileges.
- CVE-2022-41973HIGHCVSS 7.8EG 7.82022-10-29
multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can change symlinks in multipathd due to incorrect symlink hand…
- CVE-2022-40710HIGHCVSS 7.8EG 7.82022-09-28
A link following vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain th…
- CVE-2022-34893HIGHCVSS 7.8EG 7.82022-09-19
Trend Micro Security 2022 (consumer) has a link following vulnerability where an attacker with lower privileges could manipulate a mountpoint which could lead to escalation of privilege on an affected machine.
- CVE-2022-2897HIGHCVSS 7.8EG 7.82022-08-31
Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow privilege escalation..
- CVE-2021-31566HIGHCVSS 7.8EG 7.82022-08-23
An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who wo…
- CVE-2021-23177HIGHCVSS 7.8EG 7.82022-08-23
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when tryin…
- CVE-2022-36336HIGHCVSS 7.8EG 7.82022-07-30
A link following vulnerability in the scanning function of Trend Micro Apex One and Worry-Free Business Security agents could allow a local attacker to escalate privileges on affected installations. The resolution for this issue has been d…
- CVE-2022-34008HIGHCVSS 7.8EG 7.82022-06-21
Comodo Antivirus 12.2.2.8012 has a quarantine flaw that allows privilege escalation. To escalate privilege, a low-privileged attacker can use an NTFS directory junction to restore a malicious DLL from quarantine into the System32 folder.
- CVE-2022-28225HIGHCVSS 7.8EG 7.82022-06-15
Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.684 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex B…
- CVE-2021-25261HIGHCVSS 7.8EG 7.82022-06-15
Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex B…
- CVE-2022-31218HIGHCVSS 7.8EG 7.82022-06-15
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file …
- CVE-2022-31217HIGHCVSS 7.8EG 7.82022-06-15
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file …
- CVE-2022-31216HIGHCVSS 7.8EG 7.82022-06-15
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file …
- CVE-2022-26704HIGHCVSS 7.8EG 7.82022-05-26
A validation issue existed in the handling of symlinks and was addressed with improved validation of symlinks. This issue is fixed in macOS Monterey 12.4. An app may be able to gain elevated privileges.
Map vulnerabilities like CWE-59 to your infrastructure
EchelonGraph correlates every CVE — across CWE-59 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →