CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,613 vulnerabilities with CWE-59
CVE-2024-26238 HIGH
Windows 10 21H2 < 10.0.19044.4412 and 22H2 < 10.0.19045.4412 - Elevation of Privilege via PLUGScheduler Scheduled Task
CVSS 7.8
CVE-2024-3037 HIGH
PaperCut NG/MF < 23.0.9 - Arbitrary File Deletion via Web Print
CVSS 7.8
CVE-2024-31952 MEDIUM
Samsung Magician 8.0.0 - Privilege Escalation
CVSS 6.7
CVE-2024-23459 HIGH
Zscaler Client Connector <3.7 - Path Traversal
CVSS 7.1
CVE-2024-28189 CRITICAL
Judge0 <1.13.1 - Privilege Escalation
CVSS 10.0
CVE-2024-28185 CRITICAL
judge0 1.13.0 - Arbitrary File Write and Remote Code Execution via Symlink Attack
CVSS 10.0
CVE-2024-29989 HIGH
Azure Monitor Agent - Privilege Escalation
CVSS 8.4
CVE-2024-28907 HIGH
Windows Server 2022 23H2 < 10.0.25398.830 - Elevation of Privilege via Brokering File System Link Resolution
CVSS 7.8
CVE-2024-26216 HIGH
Windows Server 2008/2012/2016/2019/2022 Elevation of Privilege via File Server Resource Management Service
CVSS 7.3
CVE-2024-26158 HIGH
Windows 10/11, Windows Server 2008-2012 Elevation of Privilege via Improper Link Resolution
CVSS 7.8
CVE-2024-21447 HIGH
Windows 10/11, Server 2022 Privilege Escalation via Improper Link Resolution
CVSS 7.8
CVE-2024-25953 MEDIUM
Dell PowerScale OneFS 9.4.0.x-9.7.0.x - Denial of Service and Information Tampering via Symlink Following
CVSS 6.0
CVE-2024-25952 MEDIUM
Dell PowerScale OneFS 8.2.2.x-9.7.0.x - Denial of Service and Information Tampering via Symlink Following
CVSS 6.0
CVE-2024-29188 HIGH
WiX toolset < 3.14.1 and < 4.0.5 - Unauthenticated Directory Deletion via RemoveFolderEx Junction Attack
CVSS 7.9
CVE-2024-28916 HIGH
Xbox Gaming Services < 19.87.13001.0 - Elevation of Privilege via Improper Link Resolution
CVSS 8.8
CVE-2024-1753 HIGH
Podman < 4.9.4 and < 5.0.1 - Unauthenticated Container Escape via Symbolic Link Mount
CVSS 8.6
CVE-2024-26199 HIGH
Microsoft 365 Apps - Elevation of Privilege via Improper Link Resolution
CVSS 7.8
CVE-2024-21432 HIGH
Windows 10 - Elevation of Privilege via Improper Link Resolution
CVSS 7.0
CVE-2024-23285 MEDIUM
macOS < 14.4 - Unprotected User Data Exposure via Symlink Handling
CVSS 5.5
CVE-2024-0068 MEDIUM
HYPR Workforce Access < 8.7.1 - File Manipulation via Improper Link Resolution
CVSS 5.5
CVE-2024-21397 MEDIUM
Microsoft Azure File Sync 14.0.0.0-16.1.x - Elevation of Privilege via Improper Link Resolution
CVSS 5.3
CVE-2024-21329 HIGH
Azure Connected Machine Agent < 1.38 - Elevation of Privilege via Improper Link Resolution
CVSS 7.3
CVE-2024-1329 HIGH
HashiCorp Nomad 1.5.13-1.6.6 and 1.7.3 - Arbitrary File Write via Symlink Attack
CVSS 7.7
CVE-2024-20656 HIGH
Visual Studio - Privilege Escalation
CVSS 7.8
CVE-2024-0206 HIGH
Trellix Anti-Malware Engine - Authenticated Privilege Escalation via Symbolic Link Manipulation
CVSS 7.1
Details
Vulnerabilities 1,613
Exploit Likelihood Medium