VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,658)

page 13 of 83
  • CVE-2024-45316HigOct 11, 2024
    risk 0.51cvss 7.8epss 0.00

    The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard privileges to delete arbitrary folders and files, potentially leading to local privilege…

  • CVE-2024-43551HigOct 8, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Storage Elevation of Privilege Vulnerability

  • CVE-2024-43501HigOct 8, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

  • CVE-2024-8404HigSep 26, 2024
    risk 0.51cvss 7.8epss 0.00

    An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of…

  • CVE-2024-46744HigSep 18, 2024
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: Squashfs: sanity check symbolic link size Syzkiller reports a "KMSAN: uninit-value in pick_link" bug. This is caused by an uninitialised page, which is ultimately caused by a corrupted symbolic link size read…

  • CVE-2024-5928HigAug 21, 2024
    risk 0.51cvss 7.8epss 0.00

    VIPRE Advanced Security PMAgent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Advanced Security. An attacker must first obtain the ability to execute low-privileged…

  • CVE-2024-38098HigAug 13, 2024
    risk 0.51cvss 7.8epss 0.01

    Azure Connected Machine Agent Elevation of Privilege Vulnerability

  • CVE-2024-38084HigAug 13, 2024
    risk 0.51cvss 7.8epss 0.01

    Microsoft OfficePlus Elevation of Privilege Vulnerability

  • CVE-2024-7252HigJul 29, 2024
    risk 0.51cvss 7.8epss 0.00

    Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute…

  • CVE-2024-7251HigJul 29, 2024
    risk 0.51cvss 7.8epss 0.00

    Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute…

  • CVE-2024-7250HigJul 29, 2024
    risk 0.51cvss 7.8epss 0.00

    Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute…

  • CVE-2024-7249HigJul 29, 2024
    risk 0.51cvss 7.8epss 0.00

    Comodo Firewall Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Firewall. An attacker must first obtain the ability to execute low-privileged code on the target system…

  • CVE-2024-35261HigJul 9, 2024
    risk 0.51cvss 7.8epss 0.01

    Azure Network Watcher VM Extension Elevation of Privilege Vulnerability

  • CVE-2024-6147HigJun 20, 2024
    risk 0.51cvss 7.8epss 0.00

    Poly Plantronics Hub Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Poly Plantronics Hub. An attacker must first obtain the ability to execute low-privileged code on the…

  • CVE-2024-30104HigJun 11, 2024
    risk 0.51cvss 7.8epss 0.02

    Microsoft Office Remote Code Execution Vulnerability

  • CVE-2024-36305HigJun 10, 2024
    risk 0.51cvss 7.8epss 0.01

    A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit…

  • CVE-2024-4454HigMay 22, 2024
    risk 0.51cvss 7.8epss 0.00

    WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of WithSecure Elements Endpoint Protection. User interaction on the part of an…

  • CVE-2023-51636HigMay 22, 2024
    risk 0.51cvss 7.8epss 0.01

    Avira Prime Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avira Prime. An attacker must first obtain the ability to execute low-privileged code on the target system in order…

  • CVE-2024-30060HigMay 16, 2024
    risk 0.51cvss 7.8epss 0.00

    Azure Monitor Agent Elevation of Privilege Vulnerability

  • CVE-2024-30018HigMay 14, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability