CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,518 vulnerabilities with CWE-59
CVE-2024-38098 HIGH
Azure Connected Machine Agent - Privilege Escalation
CVSS 7.8
CVE-2024-38084 HIGH
Microsoft OfficePlus - Privilege Escalation
CVSS 7.8
CVE-2024-7252 HIGH
Comodo Internet Security Pro - Local Privilege Escalation via Symbolic Link Attack on cmdagent
CVSS 7.8
CVE-2024-7251 HIGH
Comodo Internet Security Pro - Local Privilege Escalation via Symbolic Link in cmdagent
CVSS 7.8
CVE-2024-7250 HIGH
Comodo Internet Security Pro - Local Privilege Escalation via Symbolic Link Attack in cmdagent
CVSS 7.8
CVE-2024-7249 HIGH
Comodo Firewall - Local Privilege Escalation via Symbolic Link Abuse in cmdagent
CVSS 7.8
CVE-2024-29069 MEDIUM
snapd < 2.62 - Unauthenticated Arbitrary File Read via Malicious Snap Symbolic Links
CVSS 4.8
CVE-2024-38081 HIGH
Microsoft .NET and .NET Framework - Elevation of Privilege
CVSS 7.3
CVE-2024-38022 HIGH
Windows Image Acquisition - Privilege Escalation
CVSS 7.0
CVE-2024-38013 MEDIUM
Microsoft Windows Server Backup - Privilege Escalation
CVSS 6.7
CVE-2024-35261 HIGH
Azure Network Watcher Agent < 1.4.3320.1 - Elevation of Privilege via Improper Link Resolution
CVSS 7.8
CVE-2024-6147 HIGH
Poly Plantronics Hub - Privilege Escalation
CVSS 7.8
CVE-2024-5742 MEDIUM
GNU Nano 2.2.0-8.0 - Privilege Escalation via Emergency File Symlink
CVSS 6.7
CVE-2024-35254 HIGH
Azure Monitor Agent < 1.26.0 - Elevation of Privilege via Improper Link Resolution
CVSS 7.1
CVE-2024-35253 MEDIUM
Microsoft Azure File Sync 16.0.0.0-17.2.0.0 - Elevation of Privilege via Improper Link Resolution
CVSS 4.4
CVE-2024-30104 HIGH
Microsoft 365 Apps and Office - Remote Code Execution via Improper Link Resolution
CVSS 7.8
CVE-2024-30093 HIGH
Windows Storage - Privilege Escalation
CVSS 7.3
CVE-2024-30076 MEDIUM
Windows Container Manager Service - Privilege Escalation
CVSS 6.8
CVE-2024-30065 MEDIUM
Windows 10 1507-22H2, Windows 11 21H2-23H2, Windows Server 2012-2022 - Denial of Service via Theme File Handling
CVSS 5.5
CVE-2024-35235 MEDIUM
OpenPrinting CUPS < 2.4.8 - Arbitrary File Permission Change via Symbolic Link Listen Configuration
CVSS 4.4
CVE-2024-36306 MEDIUM
Trend Micro Apex One 14.0-14.0.0.12980 - Denial of Service via Link Following
CVSS 6.1
CVE-2024-36305 HIGH
Trend Micro Apex One - Privilege Escalation
CVSS 7.8
CVE-2024-27885 MEDIUM
macOS <14.5-13.6.7-12.7.5 - Info Disclosure
CVSS 6.3
CVE-2024-5102 HIGH
Avast Antivirus <24.2 - Privilege Escalation
CVSS 7.0
CVE-2024-3829 CRITICAL
qdrant/qdrant < 1.9.0 - Arbitrary File Read and Write via Snapshot Recovery Symlink Manipulation
CVSS 9.1
Details
Vulnerabilities 1,518
Exploit Likelihood Medium