CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,520 vulnerabilities with CWE-59
CVE-2023-24904 HIGH
Windows Installer < - Privilege Escalation
CVSS 7.1
CVE-2023-28141 MEDIUM
Qualys Cloud Agent < 4.8.0.31 - Arbitrary File Write via NTFS Junction
CVSS 6.7
CVE-2023-28972 MEDIUM
Juniper Networks Junos OS - Info Disclosure
CVSS 6.8
CVE-2023-28222 HIGH
Windows Kernel - Elevation of Privilege via Improper Link Resolution
CVSS 7.1
CVE-2023-0652 HIGH
Cloudflare WARP < 2023.3.381.0 - Privilege Escalation via Hardlink Attack
CVSS 7.0
CVE-2023-1412 HIGH
Cloudflare WARP Client <=2022.12.582.0 - Privilege Escalation
CVSS 7.0
CVE-2023-25940 MEDIUM
Dell PowerScale OneFS 9.5.0.0 - Improper Link Resolution Before File Access in isi_gather_info
CVSS 6.7
CVE-2023-28642 MEDIUM
runc < 1.1.5 - AppArmor Bypass via Symlinked /proc
CVSS 6.1
CVE-2023-28892 HIGH
Malwarebytes AdwCleaner 8.4.0 - Privilege Escalation
CVSS 7.8
CVE-2023-26088 HIGH
Malwarebytes <4.5.23 - Privilege Escalation
CVSS 7.8
CVE-2023-1314 HIGH
cloudflared <= 2023.3.0 - Privilege Escalation via MSI Installer Symbolic Link Attack
CVSS 7.5
CVE-2023-24930 HIGH
Microsoft OneDrive for MacOS - Privilege Escalation
CVSS 7.8
CVE-2023-24577 MEDIUM
McAfee Total Protection <16.0.50 - Privilege Escalation
CVSS 5.5
CVE-2023-25148 HIGH
Trend Micro Apex One < 14.0.11960 - Privilege Escalation via Symlink Attack
CVSS 7.8
CVE-2023-25146 HIGH
Trend Micro Apex One < 14.0.11960 - Arbitrary File Write via Junction Link Following
CVSS 7.8
CVE-2023-25145 HIGH
Trend Micro Apex One < 14.0.11960 - Privilege Escalation via Link Following
CVSS 7.8
CVE-2023-27850 MEDIUM
NETGEAR Nighthawk WiFi6 Router < 1.0.10.94 - Arbitrary File Access via File Sharing Mechanism
CVSS 6.8
CVE-2023-23558 MEDIUM
Eternal Terminal 6.2.1 - Sensitive Information Exposure via Fixed /tmp Path
CVSS 6.3
CVE-2023-21567 MEDIUM
Visual Studio 2017 15.0-15.9.51, 2019 16.0-16.11.23, 2022 < 17.0.19 - Denial of Service via Improper Link Resolution
CVSS 5.6
CVE-2023-22490 MEDIUM
Git < 2.30.8 - Arbitrary File Read via Symbolic Link in Local Clone Optimization
CVSS 5.5
CVE-2023-21722 MEDIUM
.NET Framework - Denial of Service via Improper Link Resolution
CVSS 5.0
CVE-2023-24572 MEDIUM
Dell Command | Integration Suite for System Center <6.4.0 - Privile...
CVSS 4.7
CVE-2023-23697 MEDIUM
Dell Command | Intel vPro Out of Band < 4.4.0 - Authenticated Arbitrary Folder Deletion during Uninstallation
CVSS 4.7
CVE-2023-25168 CRITICAL
Pterodactyl Wings 1.7.0-1.7.3 and 1.11.0-1.11.3 - Authenticated Arbitrary File Deletion via Symbolic Link
CVSS 9.6
CVE-2023-25152 HIGH
Pterodactyl Wings < 1.7.3 and 1.11.x < 1.11.3 - Unauthenticated Arbitrary File Write via Symbolic Link
CVSS 8.4
Details
Vulnerabilities 1,520
Exploit Likelihood Medium