CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,522 vulnerabilities with CWE-59
CVE-2022-27883 HIGH
Trend Micro Antivirus for Mac < 11.5 - Privilege Escalation via Symlink Attack
CVSS 7.3
CVE-2022-26612 CRITICAL
Apache Hadoop < 3.2.3 - Arbitrary File Write via Symlink Bypass on Windows
CVSS 9.8
CVE-2022-0799 HIGH
Google Chrome <99.0.4844.51 - Privilege Escalation
CVSS 8.8
CVE-2022-27816 HIGH
swhkd < 1.2.0 - Denial of Service via Unsafe /tmp/swhks.pid Handling
CVSS 7.1
CVE-2022-27815 HIGH
swhkd < 1.2.0 - Denial of Service via /tmp/swhkd.pid Symlink
CVSS 7.8
CVE-2022-22995 CRITICAL
Western Digital My Cloud Firmware < 5.19.117 - Arbitrary File Write via SMB and AFP Primitives
CVSS 10.0
CVE-2022-26659 HIGH
Docker Desktop <4.6.0 - Code Injection
CVSS 7.1
CVE-2022-22585 HIGH
iPadOS < 15.3 - Improper Link Resolution Before File Access
CVSS 7.5
CVE-2022-20050 MEDIUM
Connsyslogger - Privilege Escalation
CVSS 6.7
CVE-2022-22262 HIGH
ROG Live Service < 1.3.3.0 - Unauthenticated Arbitrary File Deletion via Symbolic Link
CVSS 7.7
CVE-2022-24680 HIGH
Trend Micro Apex One <10.0 SP1 - Privilege Escalation
CVSS 7.8
CVE-2022-24679 HIGH
Trend Micro Apex One <10.0 SP1 - Privilege Escalation
CVSS 7.8
CVE-2022-24671 HIGH
Trend Micro Antivirus for Max <11.0.2150 - Privilege Escalation
CVSS 7.8
CVE-2022-25179 MEDIUM
Jenkins Pipeline Multibranch Plugin < 706.vd43c65dec013 - Arbitrary File Read via readTrusted Step
CVSS 6.5
CVE-2022-25177 MEDIUM
Jenkins Pipeline < 552.vd9cc05b8a2e1 - Arbitrary File Read via libraryResource Step
CVSS 6.5
CVE-2022-25176 MEDIUM
Jenkins Pipeline < 2648.va9433432b33c - Arbitrary File Read via Symbolic Link Following
CVSS 6.5
CVE-2022-0017 HIGH
GlobalProtect 5.1-5.1.9 and 5.2-5.2.4 - Local Privilege Escalation via Improper Link Resolution
CVSS 7.0
CVE-2022-21999 HIGH KEV
Windows Print Spooler - Privilege Escalation
CVSS 7.8
CVE-2022-21997 HIGH
Windows Print Spooler - Privilege Escalation
CVSS 7.1
CVE-2022-21944 HIGH
openSUSE watchman <4.9.0-9.1 - Privilege Escalation
CVSS 7.8
CVE-2022-0012 MEDIUM
Cortex XDR Agent Arbitrary File Deletion and DoS via Improper Link Resolution
CVSS 6.1
CVE-2022-21919 HIGH KEV
Windows User Profile Service - Privilege Escalation
CVSS 7.0
CVE-2022-21895 HIGH
Windows User Profile Service - Elevation of Privilege via Improper Link Resolution
CVSS 7.8
CVE-2022-21838 MEDIUM
Windows Cleanup Manager - Elevation of Privilege via Improper Link Resolution
CVSS 5.5
CVE-2021-47949 HIGH
CyberPanel 2.1 Authenticated Remote Code Execution via Symlink Attack
CVSS 8.8
Details
Vulnerabilities 1,522
Exploit Likelihood Medium