← Back
CWE-59

1,516 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

JSON object

Loading...

CVEs (1,516)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mcafee
1Endpoint Security
Nov 21, 2024
Sep 9, 2020
N/A· v4
8.8 HIGH· v3
4.6 MEDIUM· v2
Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to access files which the user otherwise would not have access to via manipulat...Show more
Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to access files which the user otherwise would not have access to via manipulating symbolic links to redirect McAfee file operations to an unintended file.Show less
5Canonical
DebianFedoraproject+2 more
5Ark
Debian LinuxFedora+2 more
Nov 21, 2024
Sep 2, 2020
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.
1Superantispyware
1Professional X
Nov 21, 2024
Sep 1, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivileged users to restore a malicious DLL from quarantine into the system32 folder via an NTFS directory ju...Show more
SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivileged users to restore a malicious DLL from quarantine into the system32 folder via an NTFS directory junction, as demonstrated by a crafted ualapi.dll file that is detected as malware.Show less
1Trendmicro
4Apex One
OfficescanWorry Free Business Security+1 more
Nov 21, 2024
Sep 1, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services on macOS may allow an attacker to manipulate a certain binary to load and run a script from a user-...Show more
A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services on macOS may allow an attacker to manipulate a certain binary to load and run a script from a user-writable folder, which then would allow them to execute arbitrary code as root. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.Show less
1Trendmicro
3Apex One
Worry Free Business SecurityWorry Free Business Security Services
Nov 21, 2024
Sep 1, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability in Trend Micro Apex One, OfficeScan XG SP1, Worry-Free Business Security 10 SP1 and Worry-Free Business Security Services on Microsoft Windows may allow an attacker to create a hard link to any file on th...Show more
A vulnerability in Trend Micro Apex One, OfficeScan XG SP1, Worry-Free Business Security 10 SP1 and Worry-Free Business Security Services on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Please note that version 1909 (OS Build 18363.719) of Microsoft Windows 10 mitigates hard links, but previous versions are affected.Show less
1Canonical
1Checkinstall
Nov 21, 2024
Aug 31, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
checkinstall 1.6.2, when used to create a package that contains a symlink, may trigger the creation of a mode 0777 executable file.
3Canonical
FedoraprojectTuxfamily
3Chrony
FedoraUbuntu Linux
Nov 21, 2024
Aug 24, 2020
N/A· v4
6.0 MEDIUM· v3
3.6 LOW· v2
A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while still running as the root user, and when it's opened for writ...Show more
A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while still running as the root user, and when it's opened for writing, chronyd does not check for an existing symbolic link with the same file name. This flaw allows an attacker with privileged access to create a symlink with the default PID file name pointing to any destination file in the system, resulting in data loss and a denial of service due to the path traversal.Show less
3Canonical
Net SnmpNetapp
5Cloud Backup
Net SnmpSmi S Provider+2 more
Dec 3, 2025
Aug 20, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following.
1Abbyy
1Finereader
Nov 21, 2024
Aug 13, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
ABBYY network license server in ABBYY FineReader 15 before Release 4 (aka 15.0.112.2130) allows escalation of privileges by local users via manipulations involving files and using symbolic links.
2Fedoraproject
Trustedcomputinggroup
2Fedora
Trousers
Nov 21, 2024
Aug 13, 2020
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt exis...Show more
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt existing files, which could possibly lead to a DoS attack.Show less
1Checkpoint
1Zonealarm Anti Ransomware
Nov 21, 2024
Aug 4, 2020
N/A· v4
7.4 HIGH· v3
4.4 MEDIUM· v2
ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sophisticated timed attacker can replace those files with malicious or linked content, such as exploiti...Show more
ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sophisticated timed attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic links. This allows an unprivileged user to enable escalation of privilege via local access.Show less
1Ncp E
1Secure Enterprise Client
Nov 21, 2024
Jul 28, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
NCP Secure Enterprise Client before 10.15 r47589 allows a symbolic link attack on enumusb.reg via Support Assistant.
1Overwolf
1Overwolf
Nov 21, 2024
Jul 24, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Overwolf before 0.149.2.30 mishandles Symbolic Links during updates, causing elevation of privileges.
1Adobe
1Creative Cloud Desktop Application
Nov 21, 2024
Jul 17, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful exploitation could lead to arbitrary file system write.
1Adobe
1Creative Cloud Desktop Application
Nov 21, 2024
Jul 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful exploitation could lead to privilege escalation.
1Cisco
1Sd Wan Firmware
Nov 21, 2024
Jul 16, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying filesystem of the device. The vulnerability i...Show more
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying filesystem of the device. The vulnerability is due to insufficient file scope limiting. An attacker could exploit this vulnerability by creating a specific file reference on the filesystem and then accessing it through the web-based management interface. A successful exploit could allow the attacker to read arbitrary files from the filesystem of the underlying operating system.Show less
1Mcafee
1Total Protection
Nov 21, 2024
Jul 3, 2020
N/A· v4
6.3 MEDIUM· v3
3.3 LOW· v2
Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee dele...Show more
Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on the target machine.Show less
1Obdev
1Little Snitch
Nov 21, 2024
Jun 30, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Little Snitch version 4.5.1 and older changed ownership of a directory path controlled by the user. This allowed the user to escalate to root by linking the path to a directory containing code executed by root.
1Iobit
1Malware Fighter
Nov 21, 2024
Jun 30, 2020
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IOBit Malware Fighter Pro 8.0.2.547 allows local users to gain privileges for file deletion by manipulating malicious flagged file locations with an NTFS junction and an Object Manager symbolic link.
1Iobit
1Advanced Systemcare
Nov 21, 2024
Jun 22, 2020
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
IOBit Advanced SystemCare Free 13.5.0.263 allows local users to gain privileges for file deletion by manipulating the Clean & Optimize feature with an NTFS junction and an Object Manager symbolic link.