VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,658)

page 1 of 83
  • CVE-2022-30333HigKEVMay 9, 2022
    risk 0.78cvss 7.5epss 0.99

    RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.

  • CVE-2022-21999HigKEVFeb 9, 2022
    risk 0.75cvss 7.8epss 0.42

    Windows Print Spooler Elevation of Privilege Vulnerability

  • CVE-2020-0787HigKEVMar 12, 2020
    risk 0.75cvss 7.8epss 0.43

    An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.

  • CVE-2019-0841HigKEVApr 9, 2019
    risk 0.75cvss 7.8epss 0.41

    An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836.

  • CVE-2019-1253HigKEVSep 11, 2019
    risk 0.73cvss 7.8epss 0.12

    An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID…

  • CVE-2020-0638HigKEVJan 14, 2020
    risk 0.69cvss 7.8epss 0.03

    An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'.

  • CVE-2019-1385HigKEVNov 12, 2019
    risk 0.69cvss 7.8epss 0.04

    An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to…

  • CVE-2019-1315HigKEVOct 10, 2019
    risk 0.69cvss 7.8epss 0.03

    An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1339, CVE-2019-1342.

  • CVE-2019-1130HigKEVJul 15, 2019
    risk 0.69cvss 7.8epss 0.02

    An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129.

  • CVE-2019-1129HigKEVJul 15, 2019
    risk 0.69cvss 7.8epss 0.02

    An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1130.

  • CVE-2019-1069HigKEVJun 12, 2019
    risk 0.69cvss 7.8epss 0.06

    An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploit the vulnerability, an attacker would…

  • CVE-2019-1064HigKEVJun 12, 2019
    risk 0.69cvss 7.8epss 0.07

    An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view,…

  • CVE-2023-36874HigKEVJul 11, 2023
    risk 0.68cvss 7.8epss 0.43

    Windows Error Reporting Service Elevation of Privilege Vulnerability

  • CVE-2020-0683HigKEVFeb 11, 2020
    risk 0.66cvss 7.8epss 0.08

    An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686.

  • CVE-2015-1130HigKEVApr 10, 2015
    risk 0.66cvss 7.8epss 0.10

    The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.

  • CVE-2024-57728HigKEVJan 15, 2025
    risk 0.65cvss 7.2epss 0.07

    SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.

  • CVE-2024-37143CriDec 10, 2024
    risk 0.65cvss 10.0epss 0.01

    Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell…

  • CVE-2022-22995CriMar 25, 2022
    risk 0.65cvss 10.0epss 0.03

    The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.

  • CVE-2018-5225CriMar 22, 2018
    risk 0.65cvss 9.9epss 0.03

    In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (the fixed version for 5.5.x), 5.6.0 before 5.6.5 (the fixed version for 5.6.x), 5.7.0 before 5.7.3 (the fixed version for 5.7.x),…

  • CVE-2026-63294CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.01

    A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml file when it exists as a symbolic link.…