CWE-59
1,606 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CVEs (1,606)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Local privilege escalation during installation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40278, Acronis True Image OEM (Windows) bef...Show more |
An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows attackers to gain sensitive information via /config/system.conf. |
Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform arbitrary read/write via a malicious file. (Chromium security severity: Critical) |
Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload files that are symlinks. This can be exploited to perform an arbitrary...Show more |
Microsoft Windows Defender Elevation of Privilege Vulnerability |
1Microsoft 12Windows 10 Windows 10 1607Windows 10 1809+9 moreJun 17, 2026 Aug 8, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Windows System Assessment Tool Elevation of Privilege Vulnerability |
Reliability Analysis Metrics Calculation (RacTask) Elevation of Privilege Vulnerability |
Reliability Analysis Metrics Calculation Engine (RACEng) Elevation of Privilege Vulnerability |
UnRAR before 6.2.3 allows extraction of files outside of the destination folder via symlink chains. |
An arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1 allows attackers to overwrite root-owned files by using hardlinks. |
A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vuln...Show more |
The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that directory would be recursively deleted with the permissions of the uninstalling user account. This co...Show more |
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreJun 17, 2026 Jul 11, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Error Reporting Service Elevation of Privilege Vulnerability |
1Microsoft 9Windows 10 1607 Windows 10 1809Windows 10 21h2+6 moreJun 17, 2026 Jul 11, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability |
1Microsoft 5Windows 10 21h2 Windows 10 22h2Windows 11 21h2+2 moreJun 17, 2026 Jul 11, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 Microsoft Install Service Elevation of Privilege Vulnerability |
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreJun 17, 2026 Jul 11, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Image Acquisition Elevation of Privilege Vulnerability |
1Microsoft 9Windows 10 1607 Windows 10 1809Windows 10 21h2+6 moreJun 17, 2026 Jul 11, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability |
1Microsoft 3365 Apps OfficeOffice Long Term Servicing ChannelJun 17, 2026 Jul 11, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Microsoft Office Elevation of Privilege Vulnerability |
1Microsoft 7Windows 10 1809 Windows 10 21h2Windows 10 22h2+4 moreJun 17, 2026 Jul 11, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability |
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreJun 17, 2026 Jul 11, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Installer Elevation of Privilege Vulnerability |