← Back
CWE-59

1,502 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

JSON object

Loading...

CVEs (1,502)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Pipeline\
Nov 21, 2024
Feb 15, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier follows symbolic links to locations outside of the checkout directory for the configured SCM when reading the script file (typically Jenkinsfile) for Pipelin...Show more
Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier follows symbolic links to locations outside of the checkout directory for the configured SCM when reading the script file (typically Jenkinsfile) for Pipelines, allowing attackers able to configure Pipelines to read arbitrary files on the Jenkins controller file system.Show less
1Paloaltonetworks
1Globalprotect
Nov 21, 2024
Feb 10, 2022
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
An improper link resolution before file access ('link following') vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that enables a local attacker to disrupt system processes and potentially exec...Show more
An improper link resolution before file access ('link following') vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that enables a local attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges under certain circumstances. This issue impacts: GlobalProtect app 5.1 versions earlier than GlobalProtect app 5.1.10 on Windows. GlobalProtect app 5.2 versions earlier than GlobalProtect app 5.2.5 on Windows. This issue does not affect GlobalProtect app on other platforms.Show less
1Microsoft
17Windows 10 1507
Windows 10 1607Windows 10 1809+14 more
Oct 30, 2025
Feb 9, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Print Spooler Elevation of Privilege Vulnerability
1Microsoft
10Windows 10
Windows 11Windows 7+7 more
Nov 21, 2024
Feb 9, 2022
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
Windows Print Spooler Elevation of Privilege Vulnerability
1Juce
1Juce
Nov 21, 2024
Jan 31, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
This affects the package juce-framework/JUCE before 6.1.5. This vulnerability is triggered when a malicious archive is crafted with an entry containing a symbolic link. When extracted, the symbolic link is followed outsi...Show more
This affects the package juce-framework/JUCE before 6.1.5. This vulnerability is triggered when a malicious archive is crafted with an entry containing a symbolic link. When extracted, the symbolic link is followed outside of the target dir allowing writing arbitrary files on the target host. In some cases, this can allow an attacker to execute arbitrary code. The vulnerable code is in the ZipFile::uncompressEntry function in juce_ZipFile.cpp and is executed when the archive is extracted upon calling uncompressTo() on a ZipFile object.Show less
1Opensuse
1Factory Watchman
Nov 21, 2024
Jan 26, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A UNIX Symbolic Link (Symlink) Following vulnerability in the systemd service file for watchman of openSUSE Backports SLE-15-SP3, Factory allows local attackers to escalate to root. This issue affects: openSUSE Backports...Show more
A UNIX Symbolic Link (Symlink) Following vulnerability in the systemd service file for watchman of openSUSE Backports SLE-15-SP3, Factory allows local attackers to escalate to root. This issue affects: openSUSE Backports SLE-15-SP3 watchman versions prior to 4.9.0. openSUSE Factory watchman versions prior to 4.9.0-9.1.Show less
1Leostream
1Connection Broker
Nov 21, 2024
Jan 18, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Leostream Connection Broker 9.0.40.17 allows administrators to conduct directory traversal attacks by uploading z ZIP file that contains a symbolic link.
1Paloaltonetworks
1Cortex Xdr Agent
Nov 21, 2024
Jan 12, 2022
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
An improper link resolution before file access vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables a local user to delete arbitrary system files and impact the system integri...Show more
An improper link resolution before file access vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables a local user to delete arbitrary system files and impact the system integrity or cause a denial of service condition. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12; Cortex XDR agent 6.1 versions earlier than Cortex XDR agent 6.1.9; Cortex XDR agent 7.2 versions earlier than Cortex XDR agent 7.2.4; Cortex XDR agent 7.3 versions earlier than Cortex XDR agent 7.3.2.Show less
1Microsoft
17Windows 10 1507
Windows 10 1607Windows 10 1809+14 more
Oct 30, 2025
Jan 11, 2022
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
Windows User Profile Service Elevation of Privilege Vulnerability
1Microsoft
6Windows 10
Windows 8.1Windows Server+3 more
Nov 21, 2024
Jan 11, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Windows User Profile Service Elevation of Privilege Vulnerability
1Microsoft
9Windows 10
Windows 11Windows 7+6 more
Nov 21, 2024
Jan 11, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Windows Cleanup Manager Elevation of Privilege Vulnerability
1Trendmicro
3Apex One
Worry Free Business SecurityWorry Free Business Security Services
Nov 21, 2024
Jan 10, 2022
N/A· v4
7.1 HIGH· v3
6.6 MEDIUM· v2
A link following denial-of-service vulnerability in Trend Micro Worry-Free Business Security (on prem only) could allow a local attacker to overwrite arbitrary files in the context of SYSTEM. This is similar to, but not...Show more
A link following denial-of-service vulnerability in Trend Micro Worry-Free Business Security (on prem only) could allow a local attacker to overwrite arbitrary files in the context of SYSTEM. This is similar to, but not the same as CVE-2021-44024. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.Show less
1Trendmicro
3Apex One
Worry Free Business SecurityWorry Free Business Security Services
Nov 21, 2024
Jan 10, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A link following privilege escalation vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to create a specially craft...Show more
A link following privilege escalation vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to create a specially crafted file with arbitrary content which could grant local privilege escalation on the affected system. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.Show less
1Trendmicro
3Apex One
Worry Free Business SecurityWorry Free Business Security Services
Nov 21, 2024
Jan 10, 2022
N/A· v4
7.1 HIGH· v3
6.6 MEDIUM· v2
A link following denial-of-service vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to overwrite arbitrary files i...Show more
A link following denial-of-service vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to overwrite arbitrary files in the context of SYSTEM. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.Show less
1Trendnet
1Tew 827dru Firmware
Nov 21, 2024
Dec 30, 2021
N/A· v4
6.8 MEDIUM· v3
6.9 MEDIUM· v2
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a symlink vulnerability in the bittorrent functionality. If enabled, the bittorrent functionality is vulnerable to a symlink attack that could lead to remote code execu...Show more
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a symlink vulnerability in the bittorrent functionality. If enabled, the bittorrent functionality is vulnerable to a symlink attack that could lead to remote code execution on the device. If an end user inserts a flash drive with a malicious symlink on it that the bittorrent client can write downloads to, then a user is able to download arbitrary files to any desired location on the devices filesystem, which could lead to remote code execution. Example directories vulnerable to this include "config", "downloads", and "torrents", though it should be noted that "downloads" is the only vector that allows for arbitrary files to be downloaded to arbitrary locations.Show less
1Iris Go
1Iris
Nov 21, 2024
Dec 24, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The unsafe handling of file names during upload using UploadFormFiles method may enable attackers to writ...Show more
This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The unsafe handling of file names during upload using UploadFormFiles method may enable attackers to write to arbitrary locations outside the designated target folder.Show less
1Trendmicro
4Antivirus+ Security 2021
Internet Security 2021Maximum Security 2021+1 more
Nov 21, 2024
Dec 16, 2021
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
A link following denial-of-service (DoS) vulnerability in the Trend Micro Security (Consumer) 2021 familiy of products could allow an attacker to abuse the PC Health Checkup feature of the product to create symlinks that...Show more
A link following denial-of-service (DoS) vulnerability in the Trend Micro Security (Consumer) 2021 familiy of products could allow an attacker to abuse the PC Health Checkup feature of the product to create symlinks that would allow modification of files which could lead to a denial-of-service.Show less
1Microsoft
10Windows 10
Windows 11Windows 7+7 more
Nov 21, 2024
Dec 15, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Remote Access Elevation of Privilege Vulnerability
1Microsoft
4Windows 10
Windows 11Windows Server+1 more
Nov 21, 2024
Dec 15, 2021
N/A· v4
7.3 HIGH· v3
6.9 MEDIUM· v2
Windows Setup Elevation of Privilege Vulnerability
1Microsoft
1Windows 10 Update Assistant
Nov 21, 2024
Nov 24, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
Windows 10 Update Assistant Elevation of Privilege Vulnerability