VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,658)

page 14 of 83
  • CVE-2024-26238HigMay 14, 2024
    risk 0.51cvss 7.8epss 0.01

    Microsoft PLUGScheduler Scheduled Task Elevation of Privilege Vulnerability

  • CVE-2024-3037HigMay 14, 2024
    risk 0.51cvss 7.8epss 0.00

    An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of…

  • CVE-2023-50226HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.01

    Parallels Desktop Updater Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the…

  • CVE-2023-50197HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Intel Driver & Support Assistant. An attacker must first obtain the ability to execute…

  • CVE-2023-42126HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    G DATA Total Security GDBackupSvc Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G Data Total Security. An attacker must first obtain the ability to execute…

  • CVE-2023-42125HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Avast Premium Security Sandbox Protection Link Following Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Premium Security. An attacker must first obtain the ability to execute low-privileged…

  • CVE-2023-42099HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Intel Driver & Support Assistant. An attacker must first obtain the ability to execute…

  • CVE-2023-32179HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.01

    VIPRE Antivirus Plus FPQuarTransfer Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. An attacker must first obtain the ability to execute low-privileged…

  • CVE-2023-32178HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.01

    VIPRE Antivirus Plus TelFileTransfer Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. An attacker must first obtain the ability to execute low-privileged…

  • CVE-2023-32175HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.01

    VIPRE Antivirus Plus Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. An attacker must first obtain the ability to execute low-privileged code on the…

  • CVE-2023-27347HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    G DATA Total Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G Data Total Security. An attacker must first obtain the ability to execute low-privileged code on the…

  • CVE-2024-28907HigApr 9, 2024
    risk 0.51cvss 7.8epss 0.01

    Microsoft Brokering File System Elevation of Privilege Vulnerability

  • CVE-2024-21447HigApr 9, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Authentication Elevation of Privilege Vulnerability

  • CVE-2024-26199HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Elevation of Privilege Vulnerability

  • CVE-2023-42942HigFeb 21, 2024
    risk 0.51cvss 7.8epss 0.00

    This issue was addressed with improved handling of symlinks. This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, tvOS 17.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.1. A malicious app may be able to gain root privileges.

  • CVE-2023-52338HigJan 23, 2024
    risk 0.51cvss 7.8epss 0.00

    A link following vulnerability in the Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to…

  • CVE-2023-52094HigJan 23, 2024
    risk 0.51cvss 7.8epss 0.00

    An updater link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to abuse the updater to delete an arbitrary folder, leading for a local privilege escalation on affected installations. Please note: an attacker must first obtain the…

  • CVE-2023-52092HigJan 23, 2024
    risk 0.51cvss 7.8epss 0.00

    A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit…

  • CVE-2023-52091HigJan 23, 2024
    risk 0.51cvss 7.8epss 0.00

    An anti-spyware engine link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to…

  • CVE-2023-52090HigJan 23, 2024
    risk 0.51cvss 7.8epss 0.00

    A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit…