CWE-59
Improper Link Resolution Before File Access ('Link Following')
Description
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76
CVEs mapped to this weakness (1,658)
page 13 of 83| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-45316 | Hig | 0.51 | 7.8 | 0.00 | Oct 11, 2024 | The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard privileges to delete arbitrary folders and files, potentially leading to local privilege… | ||
| CVE-2024-43551 | Hig | 0.51 | 7.8 | 0.01 | Oct 8, 2024 | Windows Storage Elevation of Privilege Vulnerability | ||
| CVE-2024-43501 | Hig | 0.51 | 7.8 | 0.01 | Oct 8, 2024 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-8404 | Hig | 0.51 | 7.8 | 0.00 | Sep 26, 2024 | An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of… | ||
| CVE-2024-46744 | Hig | 0.51 | 7.8 | 0.00 | Sep 18, 2024 | In the Linux kernel, the following vulnerability has been resolved: Squashfs: sanity check symbolic link size Syzkiller reports a "KMSAN: uninit-value in pick_link" bug. This is caused by an uninitialised page, which is ultimately caused by a corrupted symbolic link size read… | ||
| CVE-2024-5928 | Hig | 0.51 | 7.8 | 0.00 | Aug 21, 2024 | VIPRE Advanced Security PMAgent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Advanced Security. An attacker must first obtain the ability to execute low-privileged… | ||
| CVE-2024-38098 | Hig | 0.51 | 7.8 | 0.01 | Aug 13, 2024 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | ||
| CVE-2024-38084 | Hig | 0.51 | 7.8 | 0.01 | Aug 13, 2024 | Microsoft OfficePlus Elevation of Privilege Vulnerability | ||
| CVE-2024-7252 | Hig | 0.51 | 7.8 | 0.00 | Jul 29, 2024 | Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute… | ||
| CVE-2024-7251 | Hig | 0.51 | 7.8 | 0.00 | Jul 29, 2024 | Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute… | ||
| CVE-2024-7250 | Hig | 0.51 | 7.8 | 0.00 | Jul 29, 2024 | Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute… | ||
| CVE-2024-7249 | Hig | 0.51 | 7.8 | 0.00 | Jul 29, 2024 | Comodo Firewall Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Firewall. An attacker must first obtain the ability to execute low-privileged code on the target system… | ||
| CVE-2024-35261 | Hig | 0.51 | 7.8 | 0.01 | Jul 9, 2024 | Azure Network Watcher VM Extension Elevation of Privilege Vulnerability | ||
| CVE-2024-6147 | Hig | 0.51 | 7.8 | 0.00 | Jun 20, 2024 | Poly Plantronics Hub Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Poly Plantronics Hub. An attacker must first obtain the ability to execute low-privileged code on the… | ||
| CVE-2024-30104 | Hig | 0.51 | 7.8 | 0.02 | Jun 11, 2024 | Microsoft Office Remote Code Execution Vulnerability | ||
| CVE-2024-36305 | Hig | 0.51 | 7.8 | 0.01 | Jun 10, 2024 | A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit… | ||
| CVE-2024-4454 | Hig | 0.51 | 7.8 | 0.00 | May 22, 2024 | WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of WithSecure Elements Endpoint Protection. User interaction on the part of an… | ||
| CVE-2023-51636 | Hig | 0.51 | 7.8 | 0.01 | May 22, 2024 | Avira Prime Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avira Prime. An attacker must first obtain the ability to execute low-privileged code on the target system in order… | ||
| CVE-2024-30060 | Hig | 0.51 | 7.8 | 0.00 | May 16, 2024 | Azure Monitor Agent Elevation of Privilege Vulnerability | ||
| CVE-2024-30018 | Hig | 0.51 | 7.8 | 0.01 | May 14, 2024 | Windows Kernel Elevation of Privilege Vulnerability |
- risk 0.51cvss 7.8epss 0.00
The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard privileges to delete arbitrary folders and files, potentially leading to local privilege…
- risk 0.51cvss 7.8epss 0.01
Windows Storage Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of…
- risk 0.51cvss 7.8epss 0.00
In the Linux kernel, the following vulnerability has been resolved: Squashfs: sanity check symbolic link size Syzkiller reports a "KMSAN: uninit-value in pick_link" bug. This is caused by an uninitialised page, which is ultimately caused by a corrupted symbolic link size read…
- risk 0.51cvss 7.8epss 0.00
VIPRE Advanced Security PMAgent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Advanced Security. An attacker must first obtain the ability to execute low-privileged…
- risk 0.51cvss 7.8epss 0.01
Azure Connected Machine Agent Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft OfficePlus Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute…
- risk 0.51cvss 7.8epss 0.00
Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute…
- risk 0.51cvss 7.8epss 0.00
Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute…
- risk 0.51cvss 7.8epss 0.00
Comodo Firewall Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Firewall. An attacker must first obtain the ability to execute low-privileged code on the target system…
- risk 0.51cvss 7.8epss 0.01
Azure Network Watcher VM Extension Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Poly Plantronics Hub Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Poly Plantronics Hub. An attacker must first obtain the ability to execute low-privileged code on the…
- risk 0.51cvss 7.8epss 0.02
Microsoft Office Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit…
- risk 0.51cvss 7.8epss 0.00
WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of WithSecure Elements Endpoint Protection. User interaction on the part of an…
- risk 0.51cvss 7.8epss 0.01
Avira Prime Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avira Prime. An attacker must first obtain the ability to execute low-privileged code on the target system in order…
- risk 0.51cvss 7.8epss 0.00
Azure Monitor Agent Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Kernel Elevation of Privilege Vulnerability