CWE-59
Medium likelihoodImproper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
1,613 vulnerabilities with CWE-59
CVE-2024-44258
HIGH
iPadOS < 17.7.1 - Arbitrary File Write via Symlink Handling
CVSS 7.1
CVE-2024-44175
MEDIUM
macOS < 14.7.1 and < 15 - Unprotected User Data Exposure via Symlink Validation Issue
CVSS 5.5
CVE-2024-45316
HIGH
SonicWall Connect Tunnel <12.4.3.271 - Privilege Escalation
CVSS 7.8
CVE-2024-45315
MEDIUM
SonicWall Connect Tunnel <12.4.3.271 - Privilege Escalation
CVSS 5.5
CVE-2024-43603
MEDIUM
Visual Studio 2017 < 15.9.67, 2019 < 16.11.41, 2022 17.6.0-17.6.20 - Denial of Service via Collector Service
CVSS 5.5
CVE-2024-43551
HIGH
Windows 10/11, Server 2016-2022 Elevation of Privilege via Improper Link Resolution
CVSS 7.8
CVE-2024-43501
HIGH
Windows Common Log File System Driver - Elevation of Privilege via Improper Link Resolution
CVSS 7.8
CVE-2024-38097
HIGH
Azure Monitor Agent - Privilege Escalation
CVSS 7.1
CVE-2024-27458
HIGH
HP Hotkey Support - Privilege Escalation
CVSS 8.8
CVE-2024-9341
MEDIUM
containers/common < 0.60.4 - Symbolic Link Following via FIPS Mode File Path Handling
CVSS 5.4
CVE-2024-8404
HIGH
PaperCut NG/MF - Windows - File Deletion
CVSS 7.8
CVE-2024-45770
MEDIUM
Performance Co-Pilot - Privilege Escalation
CVSS 4.4
CVE-2024-46744
HIGH
Linux Kernel < 4.19.322, 4.20.0-6.10.10 DoS via Corrupted Squashfs Symbolic Link
CVSS 7.8
CVE-2024-44178
MEDIUM
macOS < 13.7, < 14.7, < 15 - Unprotected User Data Exposure via Symlink Validation Bypass
CVSS 5.5
CVE-2024-44132
HIGH
macOS < 15.0 - Sandbox Escape via Symlink Handling
CVSS 8.8
CVE-2024-44131
MEDIUM
iPadOS < 18.0 - Unprotected User Data Exposure via Symlink Validation Bypass
CVSS 5.5
CVE-2024-43470
HIGH
Azure Network Watcher Agent 1.4.3320.1-1.4.3422.1 - Elevation of Privilege via Improper Link Resolution
CVSS 7.3
CVE-2024-38188
HIGH
Azure Network Watcher VM Agent - Privilege Escalation
CVSS 7.1
CVE-2024-39578
MEDIUM
Dell PowerScale OneFS 8.2.2.x-9.8.0.1 - Denial of Service and Information Tampering via Symlink Following
CVSS 6.3
CVE-2024-5928
HIGH
VIPRE Advanced Security - Local Privilege Escalation via Symbolic Link in Patch Management Agent
CVSS 7.8
CVE-2024-38098
HIGH
Azure Connected Machine Agent - Privilege Escalation
CVSS 7.8
CVE-2024-38084
HIGH
Microsoft OfficePlus - Privilege Escalation
CVSS 7.8
CVE-2024-7252
HIGH
Comodo Internet Security Pro - Local Privilege Escalation via Symbolic Link Attack on cmdagent
CVSS 7.8
CVE-2024-7251
HIGH
Comodo Internet Security Pro - Local Privilege Escalation via Symbolic Link in cmdagent
CVSS 7.8
CVE-2024-7250
HIGH
Comodo Internet Security Pro - Local Privilege Escalation via Symbolic Link Attack in cmdagent
CVSS 7.8
Details
Vulnerabilities
1,613
Exploit Likelihood
Medium