VYPR

CWE-1386

Insecure Operation on Windows Junction / Mount Point

BaseIncomplete

Description

The product opens a file or directory, but it does not properly prevent the name from being associated with a junction or mount point to a destination that is outside of the intended control sphere.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (15)

  • CVE-2025-58074HigMay 4, 2026
    risk 0.57cvss 8.8epss 0.00

    A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store. A low-privilege user can replace files during the installation process, which may result in deletion of arbitrary files that can lead to elevation of privileges.

  • CVE-2024-7400HigSep 27, 2024
    risk 0.55cvss epss 0.00

    The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file on the Windows operating system to delete files without having proper permissions to do so.

  • CVE-2022-42291HigFeb 7, 2023
    risk 0.53cvss 8.2epss 0.00

    NVIDIA GeForce Experience contains a vulnerability in the installer, where a user installing the NVIDIA GeForce Experience software may inadvertently delete data from a linked location, which may lead to data tampering. An attacker does not have explicit control over the…

  • CVE-2023-28065MedJun 23, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability leading to privilege escalation.

  • CVE-2024-36340MedMay 13, 2025
    risk 0.43cvss 6.6epss 0.00

    A junction point vulnerability within AMD uProf can allow a local low-privileged attacker to create junction points, potentially resulting in arbitrary file deletion or disclosure.

  • CVE-2023-32474MedFeb 6, 2024
    risk 0.43cvss 6.6epss 0.00

    Dell Display Manager application, version 2.1.1.17 and prior, contain an insecure operation on windows junction/mount point. A local malicious user could potentially exploit this vulnerability during installation leading to arbitrary folder or file deletion

  • CVE-2026-41116MedJun 9, 2026
    risk 0.41cvss 6.3epss 0.00

    Dell Inventory Collector Client, versions prior to 13.8.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary File Write.

  • CVE-2023-32454MedFeb 6, 2024
    risk 0.41cvss 6.3epss 0.00

    DUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerability. A local malicious standard user could exploit the vulnerability to create arbitrary files, leading to denial of service

  • CVE-2023-28071MedJun 23, 2023
    risk 0.41cvss 6.3epss 0.00

    Dell Command | Update, Dell Update, and Alienware Update versions 4.9.0, A01 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability to create arbitrary folder leading to…

  • CVE-2023-40623MedSep 12, 2023
    risk 0.40cvss 6.2epss 0.00

    SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and link it to a directory with operating system files. On successful exploitation the attacker can delete all the operating system…

  • CVE-2023-23698MedFeb 10, 2023
    risk 0.36cvss 5.5epss 0.00

    Dell Command | Update, Dell Update, and Alienware Update versions before 4.6.0 and 4.7.1 contain Insecure Operation on Windows Junction in the installer component. A local malicious user may potentially exploit this vulnerability leading to arbitrary file delete.

  • CVE-2023-32470MedSep 8, 2023
    risk 0.33cvss 5.0epss 0.00

    Dell Digital Delivery versions prior to 5.0.82.0 contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability to create arbitrary folder leading to permanent Denial of Service (DOS).

  • CVE-2023-24572MedFeb 13, 2023
    risk 0.31cvss 4.7epss 0.00

    Dell Command | Integration Suite for System Center, versions before 6.4.0 contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulnerability leading to arbitrary folder deletion.

  • CVE-2023-23697MedFeb 13, 2023
    risk 0.31cvss 4.7epss 0.00

    Dell Command | Intel vPro Out of Band, versions before 4.4.0, contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulnerability leading to arbitrary folder deletion.

  • CVE-2023-5834LowOct 27, 2023
    risk 0.18cvss 3.8epss 0.00

    HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauthorized file system writes. Fixed in Vagrant 2.4.0.