CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,520 vulnerabilities with CWE-59
CVE-2023-36394 HIGH
Windows Search Service - Privilege Escalation
CVSS 7.0
CVE-2023-36047 HIGH
Windows 10/11 Elevation of Privilege via Improper Link Resolution
CVSS 7.8
CVE-2023-36046 HIGH
Windows 11/Server 2022 DoS via Improper Link Resolution
CVSS 7.1
CVE-2023-6069 CRITICAL
GitHub froxlor/froxlor <2.1.0 - Info Disclosure
CVSS 9.9
CVE-2023-5834 LOW
HashiCorp Vagrant < 2.4.0 - Unauthorized File System Writes via Windows Junction
CVSS 3.8
CVE-2023-42844 HIGH
macOS 12.0.0-12.7.1 - Unprotected User Data Exposure via Symlink Resolution
CVSS 7.5
CVE-2023-46655 MEDIUM
Jenkins CloudBees CD Plugin <1.1.32 - Path Traversal
CVSS 6.5
CVE-2023-46654 HIGH
Jenkins CloudBees CD Plugin <1.1.32 - Privilege Escalation
CVSS 8.1
CVE-2023-28797 MEDIUM
Zscaler Client Connector <4.1 - Code Injection
CVSS 6.3
CVE-2023-36737 HIGH
Azure Network Watcher VM Agent - Privilege Escalation
CVSS 7.8
CVE-2023-36723 HIGH
Windows Container Manager Service - Privilege Escalation
CVSS 7.8
CVE-2023-36711 HIGH
Windows Runtime C++ Template Library - Privilege Escalation
CVSS 7.8
CVE-2023-36568 HIGH
Microsoft Office Click-To-Run - Privilege Escalation
CVSS 7.0
CVE-2023-45159 HIGH
1E Client - Arbitrary File Deletion via Symbolic Link
CVSS 8.4
CVE-2023-41968 MEDIUM
iPadOS < 17.0 - Arbitrary File Read via Symlink Validation Bypass
CVSS 5.5
CVE-2023-32182 MEDIUM
openSUSE Leap 15.5 - Improper Link Resolution Before File Access in postfix
CVSS 5.9
CVE-2023-36758 HIGH
Visual Studio - Privilege Escalation
CVSS 7.8
CVE-2023-4759 HIGH
Eclipse JGit <= 6.6.0 - Arbitrary File Overwrite via Symbolic Link on Case-Insensitive Filesystem
CVSS 8.8
CVE-2023-32163 HIGH
Wacom Drivers for Windows - Local Privilege Escalation via Symbolic Link
CVSS 7.8
CVE-2023-34723 HIGH
TechView LA-5570 Wireless Gateway 1.0.19_T53 - Sensitive Information Exposure via /config/system.conf
CVSS 7.5
CVE-2023-40028 MEDIUM
Ghost < 5.59.1 - Authenticated Arbitrary File Read via Symlink Upload
CVSS 4.9
CVE-2023-38175 HIGH
Microsoft Windows Defender - Privilege Escalation
CVSS 7.8
CVE-2023-36903 HIGH
Windows System Assessment Tool - Privilege Escalation
CVSS 7.8
CVE-2023-36876 HIGH
Reliability Analysis Metrics Calculation - Privilege Escalation
CVSS 7.1
CVE-2023-35379 HIGH
Windows Server 2008 - Elevation of Privilege via RACEng Link Resolution
CVSS 7.8
Details
Vulnerabilities 1,520
Exploit Likelihood Medium