CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,520 vulnerabilities with CWE-59
CVE-2023-20008 MEDIUM
Cisco TelePresence CE - Local Privilege Escalation
CVSS 4.4
CVE-2023-21760 HIGH
Windows Print Spooler - Privilege Escalation
CVSS 7.1
CVE-2023-21725 MEDIUM
Windows Malicious Software Removal Tool - Privilege Escalation
CVSS 6.3
CVE-2023-21678 HIGH
Windows Print Spooler - Privilege Escalation
CVSS 7.8
CVE-2023-21542 HIGH
Windows Installer - Privilege Escalation
CVSS 7.0
CVE-2022-46869 HIGH
Acronis Cyber Protect Home Office <build 40278 - Privilege Escalation
CVSS 7.8
CVE-2022-48579 HIGH
UnRAR < 6.2.3 - Directory Traversal via Symlink Chains
CVSS 7.5
CVE-2022-38730 MEDIUM
Docker Desktop for Windows <4.6 - Code Injection
CVSS 6.3
CVE-2022-34292 HIGH
Docker Desktop < 4.6.0 - Arbitrary File Write via Symlink Attack on hyperv/create API
CVSS 7.1
CVE-2022-31647 HIGH
Docker Desktop < 4.6.0 - Arbitrary File Deletion via hyperv/destroy API DataFolder Symlink
CVSS 7.1
CVE-2022-43293 MEDIUM
Wacom Driver <6.3.46-1 - Arbitrary File Write
CVSS 5.9
CVE-2022-38604 HIGH
Wacom Driver <6.3.46-1 - Privilege Escalation
CVSS 7.3
CVE-2022-47188 HIGH
Generex UPS CS141 <2.06 - Info Disclosure
CVSS 7.5
CVE-2022-22582 MEDIUM
macOS < 11.6.5 - Arbitrary File Write via Symlink Validation Issue
CVSS 5.5
CVE-2022-45697 HIGH
Razer Central < 7.8.0.381 - Arbitrary File Deletion via Accounts Directory Handling
CVSS 7.8
CVE-2022-42292 MEDIUM
NVIDIA GeForce Experience < 3.27.0.112 - Privilege Escalation via Symbolic Link Attack in NVContainer
CVSS 5.0
CVE-2022-42291 HIGH
NVIDIA GeForce Experience < 3.27.0.112 - Data Tampering via Installer Windows Junction Handling
CVSS 8.2
CVE-2022-45440 MEDIUM
Zyxel AX7501-B0 Firmware < 5.17(ABPC.3)C0 - Authenticated Directory Traversal via FTP Symbolic Link Processing
CVSS 4.4
CVE-2022-3592 MEDIUM
Samba 4.17.0-4.17.1 - Symbolic Link Following via SMB1 Unix Extensions or NFS
CVSS 6.5
CVE-2022-38482 MEDIUM
Mega HOPEX 15.2.0.6110 - Improper Link Resolution Before File Access
CVSS 4.3
CVE-2022-36943 HIGH
SSZipArchive < 2.5.3 - Arbitrary File Write via Symlink Path Traversal
CVSS 8.1
CVE-2022-45798 HIGH
Trend Micro Apex One - Privilege Escalation via Damage Cleanup Engine Symbolic Link Abuse
CVSS 7.8
CVE-2022-45412 HIGH
Firefox < 107.0 and Firefox ESR < 102.5 - Information Disclosure via Symlink Resolution
CVSS 8.8
CVE-2022-4563 HIGH
Freedom of the Press SecureDrop - Symlink Following
CVSS 7.8
CVE-2022-4122 MEDIUM
Podman < 4.5.0 - Information Disclosure via Symlink Following in .containerignore and .dockerignore
CVSS 5.3
Details
Vulnerabilities 1,520
Exploit Likelihood Medium