CWE-59
1,606 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CVEs (1,606)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 8Windows 10 1809 Windows 10 21h2Windows 10 22h2+5 moreJun 17, 2026 Nov 14, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Authentication Elevation of Privilege Vulnerability |
1Microsoft 4Windows 11 21h2 Windows 11 22h2Windows 11 23h2+1 moreJun 17, 2026 Nov 14, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 Windows Authentication Denial of Service Vulnerability |
Improper Link Resolution Before File Access in GitHub repository froxlor/froxlor prior to 2.1.0.
|
In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall. |
HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauthorized file system writes. Fixed in Vagrant 2.4.0. |
1Abus 47Tvip 10000 Firmware Tvip 10001 FirmwareTvip 10005 Firmware+44 moreNov 21, 2024 Oct 26, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Due to incorrect access control, unauthenticated remote attackers can view the /video.mjpg video stream of certain ABUS TVIP cameras. |
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. A website may be able to access sensitive user data when resolving symli...Show more |
Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the directory from which artifacts are published during the 'CloudBees CD - Publish Artifact' post-build step, allowing attack...Show more |
Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the expected directory during the cleanup process of the 'CloudBees CD - Publish Artifact' post-build step, allowing attackers...Show more |
Zscaler Client Connector for Windows before 4.1 writes/deletes a configuration file inside specific folders on the disk. A malicious user can replace the folder and execute code as a privileged user.
|
Azure Network Watcher VM Agent Elevation of Privilege Vulnerability |
1Microsoft 7Windows 10 1809 Windows 10 21h2Windows 10 22h2+4 moreJun 17, 2026 Oct 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Container Manager Service Elevation of Privilege Vulnerability |
1Microsoft 11Windows 10 1507 Windows 10 1607Windows 10 1809+8 moreJun 17, 2026 Oct 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Runtime C++ Template Library Elevation of Privilege Vulnerability |
1Microsoft 3365 Apps OfficeOffice Long Term Servicing ChannelJun 17, 2026 Oct 10, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 Microsoft Office Click-To-Run Elevation of Privilege Vulnerability |
1E Client installer can perform arbitrary file deletion on protected files. A non-privileged user could provide a symbolic link or Windows junction to point to a protected directory in the installer that the 1E Client...Show more |
1Apple 5Ipados Iphone OsMacos+2 moreJun 17, 2026 Sep 27, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to read arbitr...Show more |
2Opensuse Suse3Leap Linux Enterprise High Performance ComputingSuse Linux Enterprise DesktopJun 17, 2026 Sep 19, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux Enterprise Desktop 15 SP5 postfix, SUSE SUSE Linux Enterprise High Performance Computing 15 SP5 postfix, SUSE openSUSE Lea...Show more |
Visual Studio Elevation of Privilege Vulnerability |
Arbitrary File Overwrite in Eclipse JGit <= 6.6.0 In Eclipse JGit, all versions <= 6.6.0.202305301015-r, a symbolic link present in a specially crafted git repository can be used to write a file to locations outside the...Show more |
Wacom Drivers for Windows Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Wacom Drivers for Windows. An attacker must...Show more |