← Back
CWE-59

1,606 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

JSON object

Loading...

CVEs (1,606)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hypr
1Workforce Access
Jun 17, 2026
Jan 16, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows User-Controlled Filename.This issue affects Workforce Access: before 8.7.
1Hypr
1Workforce Access
Jun 17, 2026
Jan 16, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows User-Controlled Filename.This issue affects Workforce Access: before 8.7.
1Paxtechnology
1Paydroid
Jun 17, 2026
Jan 15, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privileges by using malicious symlinks. The attacker must have shell access to the...Show more
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privileges by using malicious symlinks. The attacker must have shell access to the device in order to exploit this vulnerability.Show less
1Ibm
2Security Verify Access
Security Verify Access Docker
Jun 17, 2026
Jan 11, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to obtain root access due to improper access...Show more
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254658.Show less
1Microsoft
4Visual Studio
Visual Studio 2017Visual Studio 2019+1 more
Jun 17, 2026
Jan 9, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Visual Studio Elevation of Privilege Vulnerability
1Trellix
1Anti Malware Engine
Jun 17, 2026
Jan 9, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to potentially gain an escalation of privileges. This was achieved by adding...Show more
A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to potentially gain an escalation of privileges. This was achieved by adding an entry to the registry under the Trellix ENS registry folder with a symbolic link to files that the user wouldn't normally have permission to. After a scan, the Engine would follow the links and remove the files Show less
1Brother
1Iprint&scan
Jun 17, 2026
Dec 26, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper link resolution before file access ('Link Following') issue exists in iPrint&Scan Desktop for Windows versions 11.0.0 and earlier. A symlink attack by a malicious user may cause a Denial-of-service (DoS) conditi...Show more
Improper link resolution before file access ('Link Following') issue exists in iPrint&Scan Desktop for Windows versions 11.0.0 and earlier. A symlink attack by a malicious user may cause a Denial-of-service (DoS) condition on the PC.Show less
1Ncp E
1Secure Enterprise Client
Jun 17, 2026
Dec 25, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privileges by creating a symbolic link from a %LOCALAPPDATA%\Temp\NcpSupport* location.
1Buildkite
1Elastic Ci Stack
Jun 17, 2026
Dec 22, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A symbolic link following vulnerability in Buildkite Elastic CI for AWS versions prior to 6.7.1 and 5.22.5 allows the buildkite-agent user to change ownership of arbitrary directories via the PIPELINE_PATH variable in th...Show more
A symbolic link following vulnerability in Buildkite Elastic CI for AWS versions prior to 6.7.1 and 5.22.5 allows the buildkite-agent user to change ownership of arbitrary directories via the PIPELINE_PATH variable in the fix-buildkite-agent-builds-permissions script.Show less
1Microsoft
1Windows 11 23h2
Jun 17, 2026
Dec 12, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
1Microsoft
3Windows 10 1507
Windows Server 2008Windows Server 2012
Jun 17, 2026
Dec 12, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Kernel Elevation of Privilege Vulnerability
1Microsoft
1Azure Connected Machine Agent
Jun 17, 2026
Dec 12, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
Azure Connected Machine Agent Elevation of Privilege Vulnerability
1Ncp E
1Secure Enterprise Client
Jun 17, 2026
Dec 9, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to read registry information of the operating system by creating a symbolic link.
1Ncp E
1Secure Enterprise Client
Jun 17, 2026
Dec 9, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers read the contents of arbitrary files on the operating system by creating a symbolic link.
1Ncp E
1Secure Enterprise Client
Jun 17, 2026
Dec 9, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to delete arbitrary files on the operating system by creating a symbolic link.
1Dell
3Encryption
Endpoint Security Suite EnterpriseSecurity Management Server
Jun 17, 2026
Nov 16, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server version prior to 11.8.1 contain an Insecure Operation on Windows Junction Vulnerability during installation. A local maliciou...Show more
Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server version prior to 11.8.1 contain an Insecure Operation on Windows Junction Vulnerability during installation. A local malicious user could potentially exploit this vulnerability to create an arbitrary folder inside a restricted directory, leading to Privilege Escalation Show less
1Zoom
1Rooms
Jun 17, 2026
Nov 15, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Link following in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation of privilege via local access.
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Installer Elevation of Privilege Vulnerability
1Microsoft
4Windows 11 21h2
Windows 11 22h2Windows 11 23h2+1 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
Windows Storage Elevation of Privilege Vulnerability
1Microsoft
9Windows 10 1507
Windows 10 1607Windows 10 1809+6 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
Windows Search Service Elevation of Privilege Vulnerability