CWE-59
Medium likelihoodImproper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
1,518 vulnerabilities with CWE-59
CVE-2024-4454
HIGH
WithSecure Elements Endpoint Protection - Privilege Escalation
CVSS 7.8
CVE-2024-30060
HIGH
Azure Monitor Agent - Privilege Escalation
CVSS 7.8
CVE-2024-32002
CRITICAL
Git <2.45.1-2.39.4 - Code Injection
CVSS 9.0
CVE-2024-30033
HIGH
Windows Search Service - Privilege Escalation
CVSS 7.0
CVE-2024-30018
HIGH
Windows Kernel - Privilege Escalation
CVSS 7.8
CVE-2024-26238
HIGH
Windows 10 21H2 < 10.0.19044.4412 and 22H2 < 10.0.19045.4412 - Elevation of Privilege via PLUGScheduler Scheduled Task
CVSS 7.8
CVE-2024-3037
HIGH
PaperCut NG/MF < 23.0.9 - Arbitrary File Deletion via Web Print
CVSS 7.8
CVE-2024-31952
MEDIUM
Samsung Magician 8.0.0 - Privilege Escalation
CVSS 6.7
CVE-2024-23459
HIGH
Zscaler Client Connector <3.7 - Path Traversal
CVSS 7.1
CVE-2024-28189
CRITICAL
Judge0 <1.13.1 - Privilege Escalation
CVSS 10.0
CVE-2024-28185
CRITICAL
judge0 1.13.0 - Arbitrary File Write and Remote Code Execution via Symlink Attack
CVSS 10.0
CVE-2024-29989
HIGH
Azure Monitor Agent - Privilege Escalation
CVSS 8.4
CVE-2024-28907
HIGH
Windows Server 2022 23H2 < 10.0.25398.830 - Elevation of Privilege via Brokering File System Link Resolution
CVSS 7.8
CVE-2024-26216
HIGH
Windows Server 2008/2012/2016/2019/2022 Elevation of Privilege via File Server Resource Management Service
CVSS 7.3
CVE-2024-26158
HIGH
Windows 10/11, Windows Server 2008-2012 Elevation of Privilege via Improper Link Resolution
CVSS 7.8
CVE-2024-21447
HIGH
Windows 10/11, Server 2022 Privilege Escalation via Improper Link Resolution
CVSS 7.8
CVE-2024-25953
MEDIUM
Dell PowerScale OneFS 9.4.0.x-9.7.0.x - Denial of Service and Information Tampering via Symlink Following
CVSS 6.0
CVE-2024-25952
MEDIUM
Dell PowerScale OneFS 8.2.2.x-9.7.0.x - Denial of Service and Information Tampering via Symlink Following
CVSS 6.0
CVE-2024-29188
HIGH
WiX toolset < 3.14.1 and < 4.0.5 - Unauthenticated Directory Deletion via RemoveFolderEx Junction Attack
CVSS 7.9
CVE-2024-28916
HIGH
Xbox Gaming Services < 19.87.13001.0 - Elevation of Privilege via Improper Link Resolution
CVSS 8.8
CVE-2024-1753
HIGH
Podman < 4.9.4 and < 5.0.1 - Unauthenticated Container Escape via Symbolic Link Mount
CVSS 8.6
CVE-2024-26199
HIGH
Microsoft 365 Apps - Elevation of Privilege via Improper Link Resolution
CVSS 7.8
CVE-2024-21432
HIGH
Windows 10 - Elevation of Privilege via Improper Link Resolution
CVSS 7.0
CVE-2024-23285
MEDIUM
macOS < 14.4 - Unprotected User Data Exposure via Symlink Handling
CVSS 5.5
CVE-2024-0068
MEDIUM
HYPR Workforce Access < 8.7.1 - File Manipulation via Improper Link Resolution
CVSS 5.5
Details
Vulnerabilities
1,518
Exploit Likelihood
Medium