CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,613 vulnerabilities with CWE-59
CVE-2025-21188 MEDIUM
Azure Network Watcher < 1.4.3563.1 - Elevation of Privilege via Improper Link Resolution
CVSS 6.0
CVE-2025-0413 HIGH
Parallels Desktop - Privilege Escalation
CVSS 7.8
CVE-2025-0146 LOW
Zoom Workplace App for macOS <6.2.10 - DoS
CVSS 3.9
CVE-2025-24136 MEDIUM
macOS < 13.7.3, < 14.7.3, < 15.3 - Unauthorized Symlink Creation to Protected Disk Regions
CVSS 4.4
CVE-2025-24104 MEDIUM
iPadOS < 17.7.4 and < 18.3 - Arbitrary File Write via Malicious Backup Restore
CVSS 5.5
CVE-2025-24103 MEDIUM
macOS < 13.7.3, < 14.7.3, < 15.3 - Unprotected User Data Exposure via Symlink Validation Bypass
CVSS 5.5
CVE-2025-0377 HIGH
HashiCorp's go-slug - Path Traversal
CVSS 7.5
CVE-2025-21331 HIGH
Windows 10 1507-22H2 and Windows 11 22H2-23H2 - Elevation of Privilege via Windows Installer
CVSS 7.3
CVE-2025-21274 MEDIUM
Windows 10 1507-24H2 and Windows Server 2012-2016 - Denial of Service via Event Tracing
CVSS 5.5
CVE-2024-54554 MEDIUM
macOS < 15.1 - Unprotected User Data Exposure via Symlink Handling
CVSS 5.5
CVE-2024-54189 HIGH
Parallels Desktop for Mac <20.1.1 - Privilege Escalation
CVSS 7.8
CVE-2024-52561 HIGH
Parallels Desktop for Mac 20.1.1 - Privilege Escalation via Snapshot Symlink Ownership Manipulation
CVSS 7.8
CVE-2024-36486 HIGH
Parallels Desktop for Mac <20.1.1 - Privilege Escalation
CVSS 7.8
CVE-2024-11857 HIGH
Realtek Bluetooth HCI Adaptor - Privilege Escalation
CVSS 7.8
CVE-2024-9524 HIGH
Avira Prime <1.1.96.2 - Local Privilege Escalation
CVSS 7.8
CVE-2024-13962 HIGH
Avast Cleanup Premium <24.2.16593.17810 - Privilege Escalation
CVSS 7.8
CVE-2024-13961 HIGH
Avast Cleanup Premium <24.2.16593.17810 - Privilege Escalation
CVSS 7.8
CVE-2024-13960 HIGH
AVG TuneUp <23.4-15592 - Privilege Escalation
CVSS 7.8
CVE-2024-13959 HIGH
AVG TuneUp <24.2.16593.9844 - Local Privilege Escalation
CVSS 7.8
CVE-2024-13944 HIGH
Norton Utilities Ultimate <24.2.16862.6344 - Privilege Escalation
CVSS 7.8
CVE-2024-13759 HIGH
Avira Prime <1.1.96.2 - Privilege Escalation
CVSS 7.8
CVE-2024-12905 HIGH
tar-fs < 1.16.4, 2.0.0-2.1.2, 3.0.0-3.0.8 - Path Traversal and Arbitrary File Write via Malicious Tar Extraction
CVSS 7.5
CVE-2024-12390 HIGH
binary-husky gpt_academic - Remote Code Execution via RAR File Symlink Extraction
CVSS 8.8
CVE-2024-12216 HIGH
gluoncv 0.10.0 - Arbitrary File Write via TarSlip in ImageClassificationDataset.from_csv()
CVSS 7.1
CVE-2024-10986 HIGH
GPT Academic 3.83 - Local File Read via HotReload Symlink Handling
CVSS 8.8
Details
Vulnerabilities 1,613
Exploit Likelihood Medium