CWE-59
1,516 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CVEs (1,516)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to access files which the user otherwise would not have access to via manipulat...Show more |
5Canonical DebianFedoraproject+2 more5Ark Debian LinuxFedora+2 moreNov 21, 2024 Sep 2, 2020 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory. |
1Superantispyware 1Professional X Nov 21, 2024 Sep 1, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivileged users to restore a malicious DLL from quarantine into the system32 folder via an NTFS directory ju...Show more |
1Trendmicro 4Apex One OfficescanWorry Free Business Security+1 moreNov 21, 2024 Sep 1, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services on macOS may allow an attacker to manipulate a certain binary to load and run a script from a user-...Show more |
1Trendmicro 3Apex One Worry Free Business SecurityWorry Free Business Security ServicesNov 21, 2024 Sep 1, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in Trend Micro Apex One, OfficeScan XG SP1, Worry-Free Business Security 10 SP1 and Worry-Free Business Security Services on Microsoft Windows may allow an attacker to create a hard link to any file on th...Show more |
checkinstall 1.6.2, when used to create a package that contains a symlink, may trigger the creation of a mode 0777 executable file. |
3Canonical FedoraprojectTuxfamily3Chrony FedoraUbuntu LinuxNov 21, 2024 Aug 24, 2020 N/A· v4 6.0 MEDIUM· v3 3.6 LOW· v2 A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while still running as the root user, and when it's opened for writ...Show more |
3Canonical Net SnmpNetapp5Cloud Backup Net SnmpSmi S Provider+2 moreDec 3, 2025 Aug 20, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following. |
ABBYY network license server in ABBYY FineReader 15 before Release 4 (aka 15.0.112.2130) allows escalation of privileges by local users via manipulations involving files and using symbolic links. |
2Fedoraproject Trustedcomputinggroup2Fedora TrousersNov 21, 2024 Aug 13, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt exis...Show more |
1Checkpoint 1Zonealarm Anti Ransomware Nov 21, 2024 Aug 4, 2020 N/A· v4 7.4 HIGH· v3 4.4 MEDIUM· v2 ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sophisticated timed attacker can replace those files with malicious or linked content, such as exploiti...Show more |
1Ncp E 1Secure Enterprise Client Nov 21, 2024 Jul 28, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 NCP Secure Enterprise Client before 10.15 r47589 allows a symbolic link attack on enumusb.reg via Support Assistant. |
Overwolf before 0.149.2.30 mishandles Symbolic Links during updates, causing elevation of privileges. |
1Adobe 1Creative Cloud Desktop Application Nov 21, 2024 Jul 17, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful exploitation could lead to arbitrary file system write. |
1Adobe 1Creative Cloud Desktop Application Nov 21, 2024 Jul 17, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful exploitation could lead to privilege escalation. |
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying filesystem of the device. The vulnerability i...Show more |
Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee dele...Show more |
Little Snitch version 4.5.1 and older changed ownership of a directory path controlled by the user. This allowed the user to escalate to root by linking the path to a directory containing code executed by root. |
IOBit Malware Fighter Pro 8.0.2.547 allows local users to gain privileges for file deletion by manipulating malicious flagged file locations with an NTFS junction and an Object Manager symbolic link. |
IOBit Advanced SystemCare Free 13.5.0.263 allows local users to gain privileges for file deletion by manipulating the Clean & Optimize feature with an NTFS junction and an Object Manager symbolic link. |