CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,613 vulnerabilities with CWE-59
CVE-2025-41421 MEDIUM
TeamViewer <15.70 - Privilege Escalation
CVSS 4.7
CVE-2025-34194 HIGH
Vasion Print Virtual Appliance Host < 25.1.102 & Application < 25.1.1413 - Local Privilege Escalation
CVSS 7.8
CVE-2025-34191 HIGH
Vasion Print Virtual Appliance Host < 22.0.843 & Application < 20.0.1923 - Arbitrary File Write
CVSS 8.4
CVE-2025-55317 HIGH
Microsoft AutoUpdate - Privilege Escalation
CVSS 7.8
CVE-2025-55245 HIGH
Xbox Gaming Services < 30.104.13001.0 - Authenticated Privilege Escalation via Improper Link Resolution
CVSS 7.8
CVE-2025-58373 MEDIUM
Roo Code <3.25.23 - Privilege Escalation
CVSS 5.5
CVE-2025-43726 MEDIUM
Dell Alienware Command Center < 5.10.2.0 - Privilege Escalation via Improper Link Resolution
CVSS 6.7
CVE-2025-57749 MEDIUM
n8n < 1.106.0 - Symlink Traversal in Read/Write File Node
CVSS 6.5
CVE-2025-8612 HIGH
AOMEI Backupper Workstation - Local Privilege Escalation via Junction Link Following
CVSS 7.3
CVE-2025-5296 HIGH
Link Following - Privilege Escalation
CVSS 7.3
CVE-2025-8959 HIGH
HashiCorp go-getter < 1.7.9 - Unauthorized Read Access via Symlink Attack
CVSS 7.5
CVE-2025-43490 HIGH
HP Hotkey Support - Privilege Escalation
CVE-2025-55188 LOW
7-Zip < 25.01 - Improper Link Resolution During Extraction
CVSS 3.6
CVE-2025-54798 LOW
raszi/tmp < 0.2.4 - Arbitrary File Write via Symbolic Link
CVSS 2.5
CVE-2025-36611 HIGH
Dell Encryption and Security Management Server < 11.11.0 - Privilege Escalation via Improper Link Resolution
CVSS 7.3
CVE-2025-43252 MEDIUM
macOS Sequoia <15.6 - Info Disclosure
CVSS 6.5
CVE-2025-43220 CRITICAL
iPadOS < 17.7.9 and macOS < 13.7.7, < 14.7.7, < 15.6 - Unprotected User Data Exposure via Symlink Validation Bypass
CVSS 9.8
CVE-2025-23267 HIGH
NVIDIA Container Toolkit < 1.17.8 - Data Tampering and Denial of Service via update-ldcache Hook
CVSS 8.5
CVE-2025-7012 HIGH
Cato Networks' CatoClient for Linux <5.5 - Privilege Escalation
CVE-2025-52837 HIGH
Trend Micro Password Manager < 5.8.0.1330 - Privilege Escalation via Symbolic Link Abuse
CVSS 7.8
CVE-2025-48384 HIGH KEV
Git < 2.43.7 - Unauthenticated Arbitrary Code Execution via Submodule Path Traversal
CVSS 8.0
CVE-2025-49739 HIGH
Visual Studio 2017, 2019, 2022 - Privilege Escalation via Improper Link Resolution
CVSS 8.8
CVE-2025-49738 HIGH
Microsoft PC Manager < 3.17.4.0 - Privilege Escalation via Improper Link Resolution
CVSS 7.8
CVE-2025-49680 HIGH
Windows Performance Recorder - Denial of Service via Improper Link Resolution
CVSS 7.3
CVE-2025-48820 HIGH
Windows AppX Deployment Service - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities 1,613
Exploit Likelihood Medium