CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,463 vulnerabilities with CWE-59
CVE-2025-49680 HIGH
Microsoft Windows 10 1507 < 10.0.10240.21073 - Symlink Following
CVSS 7.3
CVE-2025-48820 HIGH
Windows AppX Deployment Service - Privilege Escalation
CVSS 7.8
CVE-2025-48799 HIGH
Windows Update Service - Privilege Escalation
CVSS 7.8
CVE-2025-21195 MEDIUM
Microsoft Azure Service Fabric < 10.1 - Symlink Following
CVSS 6.0
CVE-2025-41668 HIGH
Service Security-Profile - Privilege Escalation
CVSS 8.8
CVE-2025-41667 HIGH
Arp-Preinit - Privilege Escalation
CVSS 8.8
CVE-2025-41666 HIGH
Watchdog <version> - Privilege Escalation
CVSS 8.8
CVE-2025-53109 HIGH
Modelcontextprotocol Server-filesystem - Symlink Following
CVE-2025-3771 HIGH
SIR <1.0.3 - Path Traversal
CVSS 7.1
CVE-2025-52936 CRITICAL
yrutschle sslh <2.2.2 - Info Disclosure
CVE-2025-30642 MEDIUM
Trendmicro Deep Security Agent < 20.0.1 - Symlink Following
CVSS 5.5
CVE-2025-30641 HIGH
Trendmicro Deep Security Agent < 20.0.1 - Symlink Following
CVSS 7.8
CVE-2025-30640 HIGH
Trendmicro Deep Security Agent < 20.0.1 - Symlink Following
CVSS 7.8
CVE-2025-49157 HIGH
Trendmicro Apex One < 14.0.14492 - Symlink Following
CVSS 7.8
CVE-2025-49156 HIGH
Trendmicro Apex One < 14.0.14492 - Symlink Following
CVSS 7.0
CVE-2025-0913 MEDIUM
GO < 1.23.10 - Symlink Following
CVSS 5.5
CVE-2025-33075 HIGH
Windows Installer - Privilege Escalation
CVSS 7.8
CVE-2025-32721 HIGH
Microsoft Windows 10 1507 < 10.0.10240.21034 - Symlink Following
CVSS 7.3
CVE-2025-5474 HIGH
2BrightSparks SyncBackFree - Privilege Escalation
CVSS 7.3
CVE-2025-36564 HIGH
Dell Encryption < 11.10.2 - Symlink Following
CVSS 7.8
CVE-2025-31198 MEDIUM
Apple Macos < 13.7.5 - Symlink Following
CVSS 5.5
CVE-2025-47181 HIGH
Microsoft Edge Update < 1.3.195.61 - Symlink Following
CVSS 8.8
CVE-2025-2102 MEDIUM
HYPR Passwordless <10.1 - Privilege Escalation
CVE-2025-3908 MEDIUM
OpenVPN 3 Linux <24 - Privilege Escalation
CVSS 6.2
CVE-2025-4211 HIGH
Qt < - Privilege Escalation
Details
Vulnerabilities 1,463
Exploit Likelihood Medium