CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,613 vulnerabilities with CWE-59
CVE-2023-46654 HIGH
Jenkins CloudBees CD Plugin <1.1.32 - Privilege Escalation
CVSS 8.1
CVE-2023-28797 MEDIUM
Zscaler Client Connector <4.1 - Code Injection
CVSS 6.3
CVE-2023-36737 HIGH
Azure Network Watcher VM Agent - Privilege Escalation
CVSS 7.8
CVE-2023-36723 HIGH
Windows Container Manager Service - Privilege Escalation
CVSS 7.8
CVE-2023-36711 HIGH
Windows Runtime C++ Template Library - Privilege Escalation
CVSS 7.8
CVE-2023-36568 HIGH
Microsoft Office Click-To-Run - Privilege Escalation
CVSS 7.0
CVE-2023-45159 HIGH
1E Client - Arbitrary File Deletion via Symbolic Link
CVSS 8.4
CVE-2023-41968 MEDIUM
iPadOS < 17.0 - Arbitrary File Read via Symlink Validation Bypass
CVSS 5.5
CVE-2023-32182 MEDIUM
openSUSE Leap 15.5 - Improper Link Resolution Before File Access in postfix
CVSS 5.9
CVE-2023-36758 HIGH
Visual Studio - Privilege Escalation
CVSS 7.8
CVE-2023-4759 HIGH
Eclipse JGit <= 6.6.0 - Arbitrary File Overwrite via Symbolic Link on Case-Insensitive Filesystem
CVSS 8.8
CVE-2023-32163 HIGH
Wacom Drivers for Windows - Local Privilege Escalation via Symbolic Link
CVSS 7.8
CVE-2023-34723 HIGH
TechView LA-5570 Wireless Gateway 1.0.19_T53 - Sensitive Information Exposure via /config/system.conf
CVSS 7.5
CVE-2023-40028 MEDIUM
Ghost < 5.59.1 - Authenticated Arbitrary File Read via Symlink Upload
CVSS 4.9
CVE-2023-38175 HIGH
Microsoft Windows Defender - Privilege Escalation
CVSS 7.8
CVE-2023-36903 HIGH
Windows System Assessment Tool - Privilege Escalation
CVSS 7.8
CVE-2023-36876 HIGH
Reliability Analysis Metrics Calculation - Privilege Escalation
CVSS 7.1
CVE-2023-35379 HIGH
Windows Server 2008 - Elevation of Privilege via RACEng Link Resolution
CVSS 7.8
CVE-2023-39107 CRITICAL
NoMachine Free Edition/Enterprise Client <v8.8.1 - File Overwrite
CVSS 9.1
CVE-2023-4053 MEDIUM
Firefox <116, Firefox ESR <115.2, Thunderbird <115.2 - SSRF
CVSS 6.5
CVE-2023-4052 MEDIUM
Firefox <116 - Privilege Escalation
CVSS 6.5
CVE-2023-36874 HIGH KEV
Windows Error Reporting Service - Privilege Escalation
CVSS 7.8
CVE-2023-35353 HIGH
Windows 10 1607-22H2, Windows 11 21H2-22H2, Windows Server 2016-2022 - Elevation of Privilege via Telemetry
CVSS 7.8
CVE-2023-35347 HIGH
Windows 10/11 & Server 2022 Elevation of Privilege via Improper Link Resolution
CVSS 7.1
CVE-2023-35342 HIGH
Windows Image Acquisition - Elevation of Privilege via Improper Link Resolution
CVSS 7.8
Details
Vulnerabilities 1,613
Exploit Likelihood Medium