← Back
CWE-59

1,607 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

JSON object

Loading...

CVEs (1,607)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ncp E
1Secure Enterprise Client
Jun 17, 2026
Jul 28, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
NCP Secure Enterprise Client before 10.15 r47589 allows a symbolic link attack on enumusb.reg via Support Assistant.
1Overwolf
1Overwolf
Jun 17, 2026
Jul 24, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Overwolf before 0.149.2.30 mishandles Symbolic Links during updates, causing elevation of privileges.
1Adobe
1Creative Cloud Desktop Application
Jun 17, 2026
Jul 17, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful exploitation could lead to arbitrary file system write.
1Adobe
1Creative Cloud Desktop Application
Jun 17, 2026
Jul 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful exploitation could lead to privilege escalation.
1Cisco
1Sd Wan Firmware
Jun 17, 2026
Jul 16, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying filesystem of the device. The vulnerability i...Show more
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying filesystem of the device. The vulnerability is due to insufficient file scope limiting. An attacker could exploit this vulnerability by creating a specific file reference on the filesystem and then accessing it through the web-based management interface. A successful exploit could allow the attacker to read arbitrary files from the filesystem of the underlying operating system.Show less
1Mcafee
1Total Protection
Jun 17, 2026
Jul 3, 2020
N/A· v4
6.3 MEDIUM· v3
3.3 LOW· v2
Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee dele...Show more
Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on the target machine.Show less
1Obdev
1Little Snitch
Jun 17, 2026
Jun 30, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Little Snitch version 4.5.1 and older changed ownership of a directory path controlled by the user. This allowed the user to escalate to root by linking the path to a directory containing code executed by root.
1Iobit
1Malware Fighter
Jun 17, 2026
Jun 30, 2020
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IOBit Malware Fighter Pro 8.0.2.547 allows local users to gain privileges for file deletion by manipulating malicious flagged file locations with an NTFS junction and an Object Manager symbolic link.
1Iobit
1Advanced Systemcare
Jun 17, 2026
Jun 22, 2020
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
IOBit Advanced SystemCare Free 13.5.0.263 allows local users to gain privileges for file deletion by manipulating the Clean & Optimize feature with an NTFS junction and an Object Manager symbolic link.
2Icinga
Opensuse
3Backports Sle
IcingaLeap
Jun 17, 2026
Jun 12, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd service) executes chmod 2750 /run/icinga2/cmd. /run/icinga2 is under control of an unprivileged user by d...Show more
An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd service) executes chmod 2750 /run/icinga2/cmd. /run/icinga2 is under control of an unprivileged user by default. If /run/icinga2/cmd is a symlink, then it will by followed and arbitrary files can be changed to mode 2750 by the unprivileged icinga2 user.Show less
2Fedoraproject
Katacontainers
2Fedora
Runtime
Jun 17, 2026
Jun 10, 2020
N/A· v4
8.8 HIGH· v3
4.6 MEDIUM· v2
A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata runtime into mounting the untrusted container filesystem on any host path...Show more
A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata runtime into mounting the untrusted container filesystem on any host path, potentially allowing for code execution on the host. This issue affects: Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than 1.10.5; Kata Containers 1.9 and earlier versions.Show less
1Bitdefender
1Antivirus 2020
Jun 17, 2026
Jun 5, 2020
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
A vulnerability in the improper handling of symbolic links in Bitdefender Antivirus Free can allow an unprivileged user to substitute a quarantined file, and restore it to a privileged location. This issue affects Bitdef...Show more
A vulnerability in the improper handling of symbolic links in Bitdefender Antivirus Free can allow an unprivileged user to substitute a quarantined file, and restore it to a privileged location. This issue affects Bitdefender Antivirus Free versions prior to 1.0.17.178.Show less
1Google
1Android
Jun 17, 2026
Jun 4, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The system area allows arbitrary file overwrites via a symlink attack. The Samsung ID is SVE-2020-17183 (June 2020).
1Cisco
1Iox
Jun 17, 2026
Jun 3, 2020
N/A· v4
6.3 MEDIUM· v3
4.6 MEDIUM· v2
A vulnerability in the Cisco Application Framework component of the Cisco IOx application environment could allow an authenticated, local attacker to overwrite arbitrary files in the virtual instance that is running on t...Show more
A vulnerability in the Cisco Application Framework component of the Cisco IOx application environment could allow an authenticated, local attacker to overwrite arbitrary files in the virtual instance that is running on the affected device. The vulnerability is due to insufficient path restriction enforcement. An attacker could exploit this vulnerability by including a crafted file in an application package. An exploit could allow the attacker to overwrite files.Show less
1Cisco
1Ios Xe
Jun 17, 2026
Jun 3, 2020
N/A· v4
4.9 MEDIUM· v3
6.8 MEDIUM· v2
A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker with administrative privileges to read arbitrary files on the underlying filesystem of the d...Show more
A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker with administrative privileges to read arbitrary files on the underlying filesystem of the device. The vulnerability is due to insufficient file scope limiting. An attacker could exploit this vulnerability by creating a specific file reference on the filesystem and then accessing it through the web UI. An exploit could allow the attacker to read arbitrary files from the underlying operating system's filesystem.Show less
1Synk
1Broker
Jun 17, 2026
May 29, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users with access to Snyk's internal network by creating symlinks to match whitelisted paths.
3Fedoraproject
GoogleOpensuse
4Backports Sle
ChromeFedora+1 more
Jun 17, 2026
May 21, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Inappropriate implementation in installer in Google Chrome on OS X prior to 83.0.4103.61 allowed a local attacker to perform privilege escalation via a crafted file.
1Katacontainers
1Runtime
Jun 17, 2026
May 19, 2020
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
An improper link resolution vulnerability affects Kata Containers versions prior to 1.11.0. Upon container teardown, a malicious guest can trick the kata-runtime into unmounting any mount point on the host and all mount...Show more
An improper link resolution vulnerability affects Kata Containers versions prior to 1.11.0. Upon container teardown, a malicious guest can trick the kata-runtime into unmounting any mount point on the host and all mount points underneath it, potentiality resulting in a host DoS.Show less
1Symantec
1Endpoint Protection
Jun 17, 2026
May 11, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Symantec Endpoint Protection, prior to 14.3, may not respect file permissions when writing to log files that are replaced by symbolic links, which can lead to a potential elevation of privilege.
1Zoom
1It Installer
Jun 17, 2026
May 4, 2020
N/A· v4
8.1 HIGH· v3
8.5 HIGH· v2
The Zoom IT installer for Windows (ZoomInstallerFull.msi) prior to version 4.6.10 deletes files located in %APPDATA%\Zoom before installing an updated version of the client. Standard users are able to write to this direc...Show more
The Zoom IT installer for Windows (ZoomInstallerFull.msi) prior to version 4.6.10 deletes files located in %APPDATA%\Zoom before installing an updated version of the client. Standard users are able to write to this directory, and can write links to other directories on the machine. As the installer runs with SYSTEM privileges and follows these links, a user can cause the installer to delete files that otherwise cannot be deleted by the user.Show less