CWE-59
Medium likelihoodImproper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
1,520 vulnerabilities with CWE-59
CVE-2023-39107
CRITICAL
NoMachine Free Edition/Enterprise Client <v8.8.1 - File Overwrite
CVSS 9.1
CVE-2023-4053
MEDIUM
Firefox <116, Firefox ESR <115.2, Thunderbird <115.2 - SSRF
CVSS 6.5
CVE-2023-4052
MEDIUM
Firefox <116 - Privilege Escalation
CVSS 6.5
CVE-2023-36874
HIGH
KEV
Windows Error Reporting Service - Privilege Escalation
CVSS 7.8
CVE-2023-35353
HIGH
Windows 10 1607-22H2, Windows 11 21H2-22H2, Windows Server 2016-2022 - Elevation of Privilege via Telemetry
CVSS 7.8
CVE-2023-35347
HIGH
Windows 10/11 & Server 2022 Elevation of Privilege via Improper Link Resolution
CVSS 7.1
CVE-2023-35342
HIGH
Windows Image Acquisition - Elevation of Privilege via Improper Link Resolution
CVSS 7.8
CVE-2023-35320
HIGH
Windows 10/11 & Server 2016/2019/2022 Elevation of Privilege via Connected User Experiences and Telemetry
CVSS 7.8
CVE-2023-33148
HIGH
Microsoft Office - Privilege Escalation
CVSS 7.8
CVE-2023-32056
HIGH
Windows Server Update Service - Elevation of Privilege via Improper Link Resolution
CVSS 7.8
CVE-2023-32053
HIGH
Windows Installer - Elevation of Privilege via Improper Link Resolution
CVSS 7.8
CVE-2023-32050
HIGH
Windows Server 2008 - Elevation of Privilege via Improper Link Resolution
CVSS 7.0
CVE-2023-37206
MEDIUM
Firefox < 115.0 - Symlink Following via File Upload
CVSS 6.5
CVE-2023-27469
HIGH
Malwarebytes Anti-Exploit < 4.4.0.220 - Arbitrary File Deletion and Denial of Service via ALPC Message
CVSS 7.1
CVE-2023-32556
MEDIUM
Trend Micro Apex One < 14.0.12105 - Sensitive Information Disclosure via Link Following
CVSS 5.5
CVE-2023-28065
MEDIUM
Dell Alienware Update < 4.9.0 - Privilege Escalation via Insecure Windows Junction Handling
CVSS 6.7
CVE-2023-28071
MEDIUM
Dell Command Update, Dell Update, Alienware Update < 4.9.0 - DoS via Windows Junction Manipulation
CVSS 6.3
CVE-2023-32012
HIGH
Windows Container Manager Service - Privilege Escalation
CVSS 7.8
CVE-2023-29351
HIGH
Windows Group Policy < - Privilege Escalation
CVSS 8.1
CVE-2023-33865
HIGH
RenderDoc <1.27 - Privilege Escalation
CVSS 7.8
CVE-2023-2939
HIGH
Google Chrome < 114.0.5735.90 - Privilege Escalation via Symbolic Link
CVSS 7.8
CVE-2023-33245
HIGH
Minecraft <1.19-1.20 - Code Injection
CVSS 8.8
CVE-2023-34204
MEDIUM
imapsync <2.229 - Privilege Escalation
CVSS 6.5
CVE-2023-27529
HIGH
Wacom Tablet Driver Installer < 6.4.2-1 - Improper Link Resolution Before File Access
CVSS 7.8
CVE-2023-29343
HIGH
SysInternals Sysmon - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities
1,520
Exploit Likelihood
Medium