← Back
CWE-59

1,500 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

JSON object

Loading...

CVEs (1,500)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Azure Connected Machine Agent
Aug 16, 2024
Aug 13, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Azure Connected Machine Agent Elevation of Privilege Vulnerability
1Microsoft
1Officeplus
Aug 16, 2024
Aug 13, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Microsoft OfficePlus Elevation of Privilege Vulnerability
1Comodo
1Internet Security
Nov 21, 2024
Jul 29, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. A...Show more
Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the cmdagent executable. By creating a symbolic link, an attacker can abuse the agent to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22831.Show less
1Comodo
1Internet Security
Nov 21, 2024
Jul 29, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. A...Show more
Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the cmdagent executable. By creating a symbolic link, an attacker can abuse the agent to create a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22832.Show less
1Comodo
1Internet Security
Nov 21, 2024
Jul 29, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. A...Show more
Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the cmdagent executable. By creating a symbolic link, an attacker can abuse the agent to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22829.Show less
1Comodo
1Firewall
Nov 21, 2024
Jul 29, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Comodo Firewall Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Firewall. An attacker must first obtain the ab...Show more
Comodo Firewall Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Firewall. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the cmdagent executable. By creating a symbolic link, an attacker can abuse the application to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-21794.Show less
1Canonical
1Snapd
Nov 21, 2024
Jul 25, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap. The snap format is a squashfs file-system image and so can contain symbolic links and other file...Show more
In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap. The snap format is a squashfs file-system image and so can contain symbolic links and other file types. Various file entries within the snap squashfs image (such as icons and desktop files etc) are directly read by snapd when it is extracted. An attacker who could convince a user to install a malicious snap which contained symbolic links at these paths could then cause snapd to write out the contents of the symbolic link destination into a world-readable directory. This in-turn could allow an unprivileged user to gain access to privileged information.Show less
1Microsoft
3.net
.net FrameworkVisual Studio 2022
Nov 21, 2024
Jul 9, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Nov 21, 2024
Jul 9, 2024
N/A· v4
7.0 HIGH· v3
N/A· v2
Windows Image Acquisition Elevation of Privilege Vulnerability
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Nov 21, 2024
Jul 9, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Microsoft Windows Server Backup Elevation of Privilege Vulnerability
1Microsoft
1Azure Network Watcher Agent
Nov 21, 2024
Jul 9, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Azure Network Watcher VM Extension Elevation of Privilege Vulnerability
1Hp
1Poly Plantronics Hub
Nov 21, 2024
Jun 20, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Poly Plantronics Hub Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Poly Plantronics Hub. An attacker must first obt...Show more
Poly Plantronics Hub Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Poly Plantronics Hub. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Spokes Update Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18271.Show less
2Gnu
Redhat
2Enterprise Linux
Nano
Nov 21, 2024
Jun 12, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the runn...Show more
A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink.Show less
1Microsoft
1Azure Monitor Agent
Nov 21, 2024
Jun 11, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
Azure Monitor Agent Elevation of Privilege Vulnerability
1Microsoft
1Azure File Sync
Nov 21, 2024
Jun 11, 2024
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Microsoft Azure File Sync Elevation of Privilege Vulnerability
1Microsoft
3365 Apps
OfficeOffice Long Term Servicing Channel
May 19, 2026
Jun 11, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Microsoft Office Remote Code Execution Vulnerability
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Nov 21, 2024
Jun 11, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
Windows Storage Elevation of Privilege Vulnerability
1Microsoft
11Windows 10 1607
Windows 10 1809Windows 10 21h2+8 more
Nov 21, 2024
Jun 11, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Windows Container Manager Service Elevation of Privilege Vulnerability
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Nov 21, 2024
Jun 11, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Windows Themes Denial of Service Vulnerability
2Debian
Openprinting
2Cups
Debian Linux
Sep 26, 2025
Jun 11, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic l...Show more
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument, providing world-writable access to the target. Given that cupsd is often running as root, this can result in the change of permission of any user or system files to be world writable. Given the aforementioned Ubuntu AppArmor context, on such systems this vulnerability is limited to those files modifiable by the cupsd process. In that specific case it was found to be possible to turn the configuration of the Listen argument into full control over the cupsd.conf and cups-files.conf configuration files. By later setting the User and Group arguments in cups-files.conf, and printing with a printer configured by PPD with a `FoomaticRIPCommandLine` argument, arbitrary user and group (not root) command execution could be achieved, which can further be used on Ubuntu systems to achieve full root command execution. Commit ff1f8a623e090dee8a8aadf12a6a4b25efac143d contains a patch for the issue.Show less