← Back
CWE-59

1,606 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

JSON object

Loading...

CVEs (1,606)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
3Visual Studio 2017
Visual Studio 2019Visual Studio 2022
Jun 17, 2026
Feb 14, 2023
N/A· v4
5.6 MEDIUM· v3
N/A· v2
Visual Studio Denial of Service Vulnerability
1Git Scm
1Git
Jun 17, 2026
Feb 14, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Git is a revision control system. Using a specially-crafted repository, Git prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8 can be tricked into using its local clone o...Show more
Git is a revision control system. Using a specially-crafted repository, Git prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8 can be tricked into using its local clone optimization even when using a non-local transport. Though Git will abort local clones whose source `$GIT_DIR/objects` directory contains symbolic links, the `objects` directory itself may still be a symbolic link. These two may be combined to include arbitrary files based on known paths on the victim's filesystem within the malicious repository's working copy, allowing for data exfiltration in a similar manner as CVE-2022-39253. A fix has been prepared and will appear in v2.39.2 v2.38.4 v2.37.6 v2.36.5 v2.35.7 v2.34.7 v2.33.7 v2.32.6, v2.31.7 and v2.30.8. If upgrading is impractical, two short-term workarounds are available. Avoid cloning repositories from untrusted sources with `--recurse-submodules`. Instead, consider cloning repositories without recursively cloning their submodules, and instead run `git submodule update` at each layer. Before doing so, inspect each new `.gitmodules` file to ensure that it does not contain suspicious module URLs.Show less
1Microsoft
1.net Framework
Jun 17, 2026
Feb 14, 2023
N/A· v4
5.0 MEDIUM· v3
N/A· v2
.NET Framework Denial of Service Vulnerability
1Dell
1Command | Integration Suite For System Center
Jun 17, 2026
Feb 13, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
Dell Command | Integration Suite for System Center, versions before 6.4.0 contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulne...Show more
Dell Command | Integration Suite for System Center, versions before 6.4.0 contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulnerability leading to arbitrary folder deletion. Show less
1Dell
1Command | Intel Vpro Out Of Band
Jun 17, 2026
Feb 13, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
Dell Command | Intel vPro Out of Band, versions before 4.4.0, contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulnerability lead...Show more
Dell Command | Intel vPro Out of Band, versions before 4.4.0, contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulnerability leading to arbitrary folder deletion. Show less
1Nvidia
1Geforce Experience
Jun 17, 2026
Feb 12, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
NVIDIA GeForce Experience contains a vulnerability in the NVContainer component, where a user without administrator privileges can create a symbolic link to a file that requires elevated privileges to write to or modify...Show more
NVIDIA GeForce Experience contains a vulnerability in the NVContainer component, where a user without administrator privileges can create a symbolic link to a file that requires elevated privileges to write to or modify, which may lead to denial of service, escalation of privilege or limited data tampering. Show less
1Pterodactyl
1Wings
Jun 17, 2026
Feb 9, 2023
N/A· v4
8.2 HIGH· v3
N/A· v2
Wings is Pterodactyl's server control plane. This vulnerability can be used to delete files and directories recursively on the host system. This vulnerability can be combined with `GHSA-p8r3-83r8-jwj5` to overwrite file...Show more
Wings is Pterodactyl's server control plane. This vulnerability can be used to delete files and directories recursively on the host system. This vulnerability can be combined with `GHSA-p8r3-83r8-jwj5` to overwrite files on the host system. In order to use this exploit, an attacker must have an existing "server" allocated and controlled by Wings. This vulnerability has been resolved in version `v1.11.4` of Wings, and has been back-ported to the 1.7 release series in `v1.7.4`. Anyone running `v1.11.x` should upgrade to `v1.11.4` and anyone running `v1.7.x` should upgrade to `v1.7.4`. There are no known workarounds for this issue.Show less
1Pterodactyl
1Wings
Jun 17, 2026
Feb 8, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Wings is Pterodactyl's server control plane. Affected versions are subject to a vulnerability which can be used to create new files and directory structures on the host system that previously did not exist, potentially a...Show more
Wings is Pterodactyl's server control plane. Affected versions are subject to a vulnerability which can be used to create new files and directory structures on the host system that previously did not exist, potentially allowing attackers to change their resource allocations, promote their containers to privileged mode, or potentially add ssh authorized keys to allow the attacker access to a remote shell on the target machine. In order to use this exploit, an attacker must have an existing "server" allocated and controlled by the Wings Daemon. This vulnerability has been resolved in version `v1.11.3` of the Wings Daemon, and has been back-ported to the 1.7 release series in `v1.7.3`. Anyone running `v1.11.x` should upgrade to `v1.11.3` and anyone running `v1.7.x` should upgrade to `v1.7.3`. There are no known workarounds for this vulnerability. ### Workarounds None at this time. Show less
1Nvidia
1Geforce Experience
Jun 17, 2026
Feb 7, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
NVIDIA GeForce Experience contains a vulnerability in the installer, where a user installing the NVIDIA GeForce Experience software may inadvertently delete data from a linked location, which may lead to data tampering....Show more
NVIDIA GeForce Experience contains a vulnerability in the installer, where a user installing the NVIDIA GeForce Experience software may inadvertently delete data from a linked location, which may lead to data tampering. An attacker does not have explicit control over the exploitation of this vulnerability, which requires the user to explicitly launch the installer from the compromised directory. Show less
1Uptimed Project
1Uptimed
Jun 17, 2026
Jan 26, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
uptimed before 0.4.6-r1 on Gentoo allows local users (with access to the uptimed user account) to gain root privileges by creating a hard link within the /var/spool/uptimed directory, because there is an unsafe chown -R...Show more
uptimed before 0.4.6-r1 on Gentoo allows local users (with access to the uptimed user account) to gain root privileges by creating a hard link within the /var/spool/uptimed directory, because there is an unsafe chown -R call.Show less
1Cisco
3Roomos
Telepresence Collaboration EndpointTelepresence Tc
Jun 17, 2026
Jan 20, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
A vulnerability in the CLI of Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to overwrite arbitrary files on the local system of an affected device. This vulnerability is due to...Show more
A vulnerability in the CLI of Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to overwrite arbitrary files on the local system of an affected device. This vulnerability is due to improper access controls on files that are in the local file system. An attacker could exploit this vulnerability by placing a symbolic link in a specific location on the local file system of an affected device. A successful exploit could allow the attacker to overwrite arbitrary files on the affected device.Show less
1Zyxel
1Ax7501 B0 Firmware
Jun 17, 2026
Jan 17, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
A vulnerability exists in the FTP server of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0, which processes symbolic links on external storage media. A local authenticated attacker with administrator privileges co...Show more
A vulnerability exists in the FTP server of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0, which processes symbolic links on external storage media. A local authenticated attacker with administrator privileges could abuse this vulnerability to access the root file system by creating a symbolic link on external storage media, such as a USB flash drive, and then logging into the FTP server on a vulnerable device.Show less
2Fedoraproject
Samba
2Fedora
Samba
Jun 17, 2026
Jan 12, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A symlink following vulnerability was found in Samba, where a user can create a symbolic link that will make 'smbd' escape the configured share path. This flaw allows a remote user with access to the exported part of the...Show more
A symlink following vulnerability was found in Samba, where a user can create a symbolic link that will make 'smbd' escape the configured share path. This flaw allows a remote user with access to the exported part of the file system under a share via SMB1 unix extensions or NFS to create symlinks to files outside the 'smbd' configured share path and gain access to another restricted server's filesystem.Show less
1Microsoft
10Windows 10
Windows 11Windows 7+7 more
Jun 17, 2026
Jan 10, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
Windows Print Spooler Elevation of Privilege Vulnerability
1Microsoft
1Windows Malicious Software Removal Tool
Jun 17, 2026
Jan 10, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Windows Malicious Software Removal Tool Elevation of Privilege Vulnerability
1Microsoft
15Windows 10 1607
Windows 10 1809Windows 10 20h2+12 more
Jun 17, 2026
Jan 10, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Print Spooler Elevation of Privilege Vulnerability
1Microsoft
9Windows 10 1607
Windows 7Windows 8.1+6 more
Jun 17, 2026
Jan 10, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
Windows Installer Elevation of Privilege Vulnerability
1Mega
1Hopex
Jun 17, 2026
Jan 10, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A link-manipulation issue was discovered in Mega HOPEX 15.2.0.6110 before V5CP4.
1Ziparchive Project
1Ziparchive
Jun 17, 2026
Jan 3, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on the filesystem when opening a malicious ZI...Show more
SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on the filesystem when opening a malicious ZIP containing a symlink as the first item.Show less
1Microsoft
1Binwalk
Jun 17, 2026
Dec 27, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A vulnerability, which was classified as problematic, was found in ReFirm Labs binwalk up to 2.3.2. Affected is an unknown function of the file src/binwalk/modules/extractor.py of the component Archive Extraction Handler...Show more
A vulnerability, which was classified as problematic, was found in ReFirm Labs binwalk up to 2.3.2. Affected is an unknown function of the file src/binwalk/modules/extractor.py of the component Archive Extraction Handler. The manipulation leads to symlink following. It is possible to launch the attack remotely. Upgrading to version 2.3.3 is able to address this issue. The name of the patch is fa0c0bd59b8588814756942fe4cb5452e76c1dcd. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216876.Show less