CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,613 vulnerabilities with CWE-59
CVE-2025-48799 HIGH
Windows Update Service - Privilege Escalation
CVSS 7.8
CVE-2025-21195 MEDIUM
Azure Service Fabric - Privilege Escalation via Improper Link Resolution
CVSS 6.0
CVE-2025-41668 HIGH
Service Security-Profile - Privilege Escalation
CVSS 8.8
CVE-2025-41667 HIGH
PHOENIX CONTACT AXC F 1152/2152/3152, BPC 9102S, RFC 4072S < 2025.0.2 - Unauthenticated Arbitrary File Write
CVSS 8.8
CVE-2025-41666 HIGH
Watchdog <version> - Privilege Escalation
CVSS 8.8
CVE-2025-53109 HIGH
Model Context Protocol Servers < 0.6.4 and < 2025.7.01 - Unintended File Access via Symlink Resolution
CVE-2025-3771 HIGH
Trellix System Information Reporter < 1.0.3 - Authenticated Arbitrary File Write via Symbolic Link Manipulation
CVSS 7.1
CVE-2025-52936 CRITICAL
yrutschle sslh <2.2.2 - Info Disclosure
CVE-2025-30642 MEDIUM
Trend Micro Deep Security Agent < 20.0.1 - Denial of Service via Link Following
CVSS 5.5
CVE-2025-30641 HIGH
Trend Micro Deep Security Agent < 20.0.1 - Privilege Escalation via Link Following
CVSS 7.8
CVE-2025-30640 HIGH
Trend Micro Deep Security Agent - Privilege Escalation via Link Following
CVSS 7.8
CVE-2025-49157 HIGH
Trend Micro Apex One < 14.0.14492 and 14.0.0.12994-14.0.0.14002 - Local Privilege Escalation via Damage Cleanup Engine
CVSS 7.8
CVE-2025-49156 HIGH
Trend Micro Apex One < 14.0.14492 & 14.0.0.12994-14.0.0.14002 Local Privilege Escalation
CVSS 7.0
CVE-2025-0913 MEDIUM
GO < 1.23.10 - Symlink Following
CVSS 5.5
CVE-2025-33075 HIGH
Windows Installer - Privilege Escalation
CVSS 7.8
CVE-2025-32721 HIGH
Windows 10/11, Server 2016-2019 Privilege Escalation via Recovery Driver Link Following
CVSS 7.3
CVE-2025-5474 HIGH
2BrightSparks SyncBackFree - Privilege Escalation
CVSS 7.3
CVE-2025-36564 HIGH
Dell Encryption < 11.10.2 - Privilege Escalation via Improper Link Resolution
CVSS 7.8
CVE-2025-31198 MEDIUM
macOS < 13.7.5, < 14.7.5, < 15.4 - Path Traversal via Symlink Validation Bypass
CVSS 5.5
CVE-2025-47181 HIGH
Microsoft Edge Update < 1.3.195.61 - Authenticated Privilege Escalation via Improper Link Resolution
CVSS 8.8
CVE-2025-2102 MEDIUM
HYPR Passwordless <10.1 - Privilege Escalation
CVE-2025-3908 MEDIUM
OpenVPN 3 Linux <24 - Privilege Escalation
CVSS 6.2
CVE-2025-4211 HIGH
Qt < - Privilege Escalation
CVE-2025-20003 HIGH
Intel(R) Graphics Driver - Privilege Escalation
CVSS 8.2
CVE-2025-29975 HIGH
Microsoft PC Manager - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities 1,613
Exploit Likelihood Medium