← Back
CWE-59

1,501 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

JSON object

Loading...

CVEs (1,501)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Netgear
1Rax30 Firmware
Jan 3, 2025
May 3, 2024
N/A· v4
4.6 MEDIUM· v3
N/A· v2
NETGEAR RAX30 USB Share Link Following Information Disclosure Vulnerability. This vulnerability allows physically present attackers to disclose sensitive information on affected installations of NETGEAR RAX30 routers. Au...Show more
NETGEAR RAX30 USB Share Link Following Information Disclosure Vulnerability. This vulnerability allows physically present attackers to disclose sensitive information on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of symbolic links on removable USB media. By creating a symbolic link, an attacker can abuse the router's web server to access arbitrary local files. An attacker can leverage this vulnerability to disclose information in the context of root. Was ZDI-CAN-19498.Show less
1Vipre
1Antivirus
Aug 8, 2025
May 3, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
VIPRE Antivirus Plus FPQuarTransfer Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. An attacker...Show more
VIPRE Antivirus Plus FPQuarTransfer Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the FPQuarTransfer method. By creating a symbolic link, an attacker can abuse the method to delete arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. . Was ZDI-CAN-19397.Show less
1Vipre
1Antivirus
Aug 8, 2025
May 3, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
VIPRE Antivirus Plus TelFileTransfer Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. An attacke...Show more
VIPRE Antivirus Plus TelFileTransfer Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the TelFileTransfer method. By creating a symbolic link, an attacker can abuse the method to delete arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. . Was ZDI-CAN-19396.Show less
1Vipre
1Antivirus
Aug 8, 2025
May 3, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
VIPRE Antivirus Plus Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. An attacker must first obt...Show more
VIPRE Antivirus Plus Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Anti Malware Service. By creating a symbolic link, an attacker can abuse the service to create arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18899.Show less
1Gdata Software
1Total Security
Aug 13, 2025
May 3, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
G DATA Total Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G Data Total Security. An attacker must first o...Show more
G DATA Total Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G Data Total Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the G DATA Backup Service. By creating a symbolic link, an attacker can abuse the service to create arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18749.Show less
1Zscaler
1Client Connector
Feb 17, 2026
May 2, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Mac allows a system file to be overwritten.This issue affects Zscaler Client Connector on Mac : before 3.7.
1Zscaler
1Client Connector
Mar 2, 2026
May 2, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Windows allows a system file to be overwritten.This issue affects Client Connector on Windows: before 3.7.
-
-
Nov 21, 2024
Apr 18, 2024
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Judge0 is an open-source online code execution system. The application uses the UNIX chown command on an untrusted file within the sandbox. An attacker can abuse this by creating a symbolic link (symlink) to a file outsi...Show more
Judge0 is an open-source online code execution system. The application uses the UNIX chown command on an untrusted file within the sandbox. An attacker can abuse this by creating a symbolic link (symlink) to a file outside the sandbox, allowing the attacker to run chown on arbitrary files outside of the sandbox. This vulnerability is not impactful on it's own, but it can be used to bypass the patch for CVE-2024-28185 and obtain a complete sandbox escape. This vulnerability is fixed in 1.13.1.Show less
-
-
Nov 21, 2024
Apr 18, 2024
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Judge0 is an open-source online code execution system. The application does not account for symlinks placed inside the sandbox directory, which can be leveraged by an attacker to write to arbitrary files and gain code ex...Show more
Judge0 is an open-source online code execution system. The application does not account for symlinks placed inside the sandbox directory, which can be leveraged by an attacker to write to arbitrary files and gain code execution outside of the sandbox. When executing a submission, Judge0 writes a `run_script` to the sandbox directory. The security issue is that an attacker can create a symbolic link (symlink) at the path `run_script` before this code is executed, resulting in the `f.write` writing to an arbitrary file on the unsandboxed system. An attacker can leverage this vulnerability to overwrite scripts on the system and gain code execution outside of the sandbox. Show less
1Microsoft
1Azure Monitor Agent
Jan 9, 2025
Apr 9, 2024
N/A· v4
8.4 HIGH· v3
N/A· v2
Azure Monitor Agent Elevation of Privilege Vulnerability
1Microsoft
1Windows Server 2022 23h2
Dec 5, 2024
Apr 9, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Microsoft Brokering File System Elevation of Privilege Vulnerability
1Microsoft
6Windows Server 2008
Windows Server 2012Windows Server 2016+3 more
Jan 8, 2025
Apr 9, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
Windows File Server Resource Management Service Elevation of Privilege Vulnerability
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Dec 6, 2024
Apr 9, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Microsoft Install Service Elevation of Privilege Vulnerability
1Microsoft
7Windows 10 21h2
Windows 10 22h2Windows 11 21h2+4 more
Jan 8, 2025
Apr 9, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Authentication Elevation of Privilege Vulnerability
1Dell
1Powerscale Onefs
Feb 20, 2026
Mar 28, 2024
N/A· v4
6.0 MEDIUM· v3
N/A· v2
Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of...Show more
Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service, information tampering.Show less
1Dell
1Powerscale Onefs
Feb 20, 2026
Mar 28, 2024
N/A· v4
6.0 MEDIUM· v3
N/A· v2
Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of...Show more
Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service, information tampering.Show less
-
-
Nov 21, 2024
Mar 24, 2024
N/A· v4
7.9 HIGH· v3
N/A· v2
WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The custom action behind WiX's `RemoveFolderEx` functionality could allow a standard user to delete protected director...Show more
WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The custom action behind WiX's `RemoveFolderEx` functionality could allow a standard user to delete protected directories. `RemoveFolderEx` deletes an entire directory tree during installation or uninstallation. It does so by recursing every subdirectory starting at a specified directory and adding each subdirectory to the list of directories Windows Installer should delete. If the setup author instructed `RemoveFolderEx` to delete a per-user folder from a per-machine installer, an attacker could create a directory junction in that per-user folder pointing to a per-machine, protected directory. Windows Installer, when executing the per-machine installer after approval by an administrator, would delete the target of the directory junction. This vulnerability is fixed in 3.14.1 and 4.0.5.Show less
1Microsoft
1Xbox Gaming Services
Jan 8, 2025
Mar 21, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Xbox Gaming Services Elevation of Privilege Vulnerability
-
-
Nov 26, 2024
Mar 18, 2024
N/A· v4
8.6 HIGH· v3
N/A· v2
A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers. A malicious Containerfile can use a dummy image with a symbol...Show more
A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers. A malicious Containerfile can use a dummy image with a symbolic link to the root filesystem as a mount source and cause the mount operation to mount the host root filesystem inside the RUN step. The commands inside the RUN step will then have read-write access to the host filesystem, allowing for full container escape at build time.Show less
1Microsoft
1365 Apps
Dec 6, 2024
Mar 12, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Microsoft Office Elevation of Privilege Vulnerability