CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,613 vulnerabilities with CWE-59
CVE-2023-35320 HIGH
Windows 10/11 & Server 2016/2019/2022 Elevation of Privilege via Connected User Experiences and Telemetry
CVSS 7.8
CVE-2023-33148 HIGH
Microsoft Office - Privilege Escalation
CVSS 7.8
CVE-2023-32056 HIGH
Windows Server Update Service - Elevation of Privilege via Improper Link Resolution
CVSS 7.8
CVE-2023-32053 HIGH
Windows Installer - Elevation of Privilege via Improper Link Resolution
CVSS 7.8
CVE-2023-32050 HIGH
Windows Server 2008 - Elevation of Privilege via Improper Link Resolution
CVSS 7.0
CVE-2023-37206 MEDIUM
Firefox < 115.0 - Symlink Following via File Upload
CVSS 6.5
CVE-2023-27469 HIGH
Malwarebytes Anti-Exploit < 4.4.0.220 - Arbitrary File Deletion and Denial of Service via ALPC Message
CVSS 7.1
CVE-2023-32556 MEDIUM
Trend Micro Apex One < 14.0.12105 - Sensitive Information Disclosure via Link Following
CVSS 5.5
CVE-2023-28065 MEDIUM
Dell Alienware Update < 4.9.0 - Privilege Escalation via Insecure Windows Junction Handling
CVSS 6.7
CVE-2023-28071 MEDIUM
Dell Command Update, Dell Update, Alienware Update < 4.9.0 - DoS via Windows Junction Manipulation
CVSS 6.3
CVE-2023-32012 HIGH
Windows Container Manager Service - Privilege Escalation
CVSS 7.8
CVE-2023-29351 HIGH
Windows Group Policy < - Privilege Escalation
CVSS 8.1
CVE-2023-33865 HIGH
RenderDoc <1.27 - Privilege Escalation
CVSS 7.8
CVE-2023-2939 HIGH
Google Chrome < 114.0.5735.90 - Privilege Escalation via Symbolic Link
CVSS 7.8
CVE-2023-33245 HIGH
Minecraft <1.19-1.20 - Code Injection
CVSS 8.8
CVE-2023-34204 MEDIUM
imapsync <2.229 - Privilege Escalation
CVSS 6.5
CVE-2023-27529 HIGH
Wacom Tablet Driver Installer < 6.4.2-1 - Improper Link Resolution Before File Access
CVSS 7.8
CVE-2023-29343 HIGH
SysInternals Sysmon - Privilege Escalation
CVSS 7.8
CVE-2023-24904 HIGH
Windows Installer < - Privilege Escalation
CVSS 7.1
CVE-2023-28141 MEDIUM
Qualys Cloud Agent < 4.8.0.31 - Arbitrary File Write via NTFS Junction
CVSS 6.7
CVE-2023-28972 MEDIUM
Juniper Networks Junos OS - Info Disclosure
CVSS 6.8
CVE-2023-28222 HIGH
Windows Kernel - Elevation of Privilege via Improper Link Resolution
CVSS 7.1
CVE-2023-0652 HIGH
Cloudflare WARP < 2023.3.381.0 - Privilege Escalation via Hardlink Attack
CVSS 7.0
CVE-2023-1412 HIGH
Cloudflare WARP Client <=2022.12.582.0 - Privilege Escalation
CVSS 7.0
CVE-2023-25940 MEDIUM
Dell PowerScale OneFS 9.5.0.0 - Improper Link Resolution Before File Access in isi_gather_info
CVSS 6.7
Details
Vulnerabilities 1,613
Exploit Likelihood Medium