← Back
CWE-59

1,606 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

JSON object

Loading...

CVEs (1,606)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Acronis
1Cyber Protect Home Office
Jun 17, 2026
Aug 31, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Local privilege escalation during installation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40278, Acronis True Image OEM (Windows) bef...Show more
Local privilege escalation during installation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40278, Acronis True Image OEM (Windows) before build 42575.Show less
1Jaycar
1La5570 Firmware
Jun 17, 2026
Aug 25, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows attackers to gain sensitive information via /config/system.conf.
1Google
1Chrome
Jun 17, 2026
Aug 25, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform arbitrary read/write via a malicious file. (Chromium security severity: Critical)
1Ghost
1Ghost
Jun 17, 2026
Aug 15, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload files that are symlinks. This can be exploited to perform an arbitrary...Show more
Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload files that are symlinks. This can be exploited to perform an arbitrary file read of any file on the host operating system. Site administrators can check for exploitation of this issue by looking for unknown symlinks within Ghost's `content/` folder. Version 5.59.1 contains a fix for this issue. All users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Microsoft
1Windows Defender
Jun 17, 2026
Aug 8, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Microsoft Windows Defender Elevation of Privilege Vulnerability
1Microsoft
12Windows 10
Windows 10 1607Windows 10 1809+9 more
Jun 17, 2026
Aug 8, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Windows System Assessment Tool Elevation of Privilege Vulnerability
1Microsoft
1Windows Server 2008
Jun 17, 2026
Aug 8, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
Reliability Analysis Metrics Calculation (RacTask) Elevation of Privilege Vulnerability
1Microsoft
1Windows Server 2008
Jun 17, 2026
Aug 8, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Reliability Analysis Metrics Calculation Engine (RACEng) Elevation of Privilege Vulnerability
1Rarlab
1Unrar
Jun 17, 2026
Aug 7, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
UnRAR before 6.2.3 allows extraction of files outside of the destination folder via symlink chains.
1Nomachine
1Nomachine
Jun 17, 2026
Aug 4, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1 allows attackers to overwrite root-owned files by using hardlinks.
1Mozilla
1Firefox
Jun 17, 2026
Aug 1, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vuln...Show more
A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2.Show less
1Mozilla
2Firefox
Firefox Esr
Jun 17, 2026
Aug 1, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that directory would be recursively deleted with the permissions of the uninstalling user account. This co...Show more
The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that directory would be recursively deleted with the permissions of the uninstalling user account. This could be combined with creation of a junction (a form of symbolic link) to allow arbitrary file deletion controlled by the non-privileged user. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116, Firefox ESR < 115.1, and Thunderbird < 115.1.Show less
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Jun 17, 2026
Jul 11, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Error Reporting Service Elevation of Privilege Vulnerability
1Microsoft
9Windows 10 1607
Windows 10 1809Windows 10 21h2+6 more
Jun 17, 2026
Jul 11, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Connected User Experiences and Telemetry Elevation of Privilege Vulnerability
1Microsoft
5Windows 10 21h2
Windows 10 22h2Windows 11 21h2+2 more
Jun 17, 2026
Jul 11, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
Microsoft Install Service Elevation of Privilege Vulnerability
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Jun 17, 2026
Jul 11, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Image Acquisition Elevation of Privilege Vulnerability
1Microsoft
9Windows 10 1607
Windows 10 1809Windows 10 21h2+6 more
Jun 17, 2026
Jul 11, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Connected User Experiences and Telemetry Elevation of Privilege Vulnerability
1Microsoft
3365 Apps
OfficeOffice Long Term Servicing Channel
Jun 17, 2026
Jul 11, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Microsoft Office Elevation of Privilege Vulnerability
1Microsoft
7Windows 10 1809
Windows 10 21h2Windows 10 22h2+4 more
Jun 17, 2026
Jul 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Jun 17, 2026
Jul 11, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Installer Elevation of Privilege Vulnerability