CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,520 vulnerabilities with CWE-59
CVE-2023-7216 MEDIUM
GNU cpio - Path Traversal via Symlink Handling
CVSS 5.3
CVE-2023-52138 HIGH
Engrampa < 1.26.2 - Path Traversal and Remote Code Execution via CPIO Archive Symlink Handling
CVSS 8.2
CVE-2023-52338 HIGH
Trend Micro Deep Security 20.0 - Privilege Escalation via Link Following
CVSS 7.8
CVE-2023-52094 HIGH
Trend Micro Apex One - Privilege Escalation
CVSS 7.8
CVE-2023-52092 HIGH
Trend Micro Apex One - Privilege Escalation
CVSS 7.8
CVE-2023-52091 HIGH
Trend Micro Apex One - Privilege Escalation
CVSS 7.8
CVE-2023-52090 HIGH
Trend Micro Apex One - Privilege Escalation
CVSS 7.8
CVE-2023-47192 HIGH
Trend Micro Apex One - Privilege Escalation via Agent Link Vulnerability
CVSS 7.8
CVE-2023-6336 HIGH
HYPR Workforce Access <8.7 - Path Traversal
CVSS 7.2
CVE-2023-6335 MEDIUM
HYPR Workforce Access <8.7 - Path Traversal
CVSS 6.4
CVE-2023-42137 HIGH
PAX PayDroid < 8.1.0_sagittarius_11.1.50_20230614 - Authenticated Privilege Escalation via Symlink Attack
CVSS 7.8
CVE-2023-31003 HIGH
IBM Security Verify Access - Privilege Escalation
CVSS 8.4
CVE-2023-51654 MEDIUM
Brother iPrint&Scan < 11.0.0 - Denial of Service via Symlink Attack
CVSS 5.5
CVE-2023-28872 HIGH
NCP Secure Enterprise Client <13.10 - RCE
CVSS 8.8
CVE-2023-43116 HIGH
Buildkite Elastic CI - Privilege Escalation
CVSS 7.8
CVE-2023-36391 HIGH
Local Security Authority Subsystem Service - Privilege Escalation
CVSS 7.8
CVE-2023-35633 HIGH
Windows 10 1507 < 10.0.10240.20345 - Privilege Escalation via Improper Link Resolution
CVSS 7.8
CVE-2023-35624 HIGH
Azure Connected Machine Agent < 1.37 - Elevation of Privilege via Improper Link Resolution
CVSS 7.3
CVE-2023-28871 MEDIUM
NCP Secure Enterprise Client <12.22 - Info Disclosure
CVSS 4.3
CVE-2023-28869 MEDIUM
NCP Secure Enterprise Client <12.22 - Info Disclosure
CVSS 6.5
CVE-2023-28868 HIGH
NCP Secure Enterprise Client <12.22 - Privilege Escalation
CVSS 8.1
CVE-2023-39246 MEDIUM
Dell Endpoint Security Suite Enterprise < 11.8.1 - Privilege Escalation via Windows Junction
CVSS 4.6
CVE-2023-43590 HIGH
Zoom Rooms for macOS <5.16.0 - Privilege Escalation
CVSS 7.8
CVE-2023-36705 HIGH
Windows Installer < - Privilege Escalation
CVSS 7.8
CVE-2023-36399 HIGH
Windows Storage - Privilege Escalation
CVSS 7.1
Details
Vulnerabilities 1,520
Exploit Likelihood Medium