CWE-59
Improper Link Resolution Before File Access ('Link Following')
Description
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76
CVEs mapped to this weakness (1,658)
page 14 of 83| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-26238 | Hig | 0.51 | 7.8 | 0.01 | May 14, 2024 | Microsoft PLUGScheduler Scheduled Task Elevation of Privilege Vulnerability | ||
| CVE-2024-3037 | Hig | 0.51 | 7.8 | 0.00 | May 14, 2024 | An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of… | ||
| CVE-2023-50226 | Hig | 0.51 | 7.8 | 0.01 | May 3, 2024 | Parallels Desktop Updater Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the… | ||
| CVE-2023-50197 | Hig | 0.51 | 7.8 | 0.00 | May 3, 2024 | Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Intel Driver & Support Assistant. An attacker must first obtain the ability to execute… | ||
| CVE-2023-42126 | Hig | 0.51 | 7.8 | 0.00 | May 3, 2024 | G DATA Total Security GDBackupSvc Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G Data Total Security. An attacker must first obtain the ability to execute… | ||
| CVE-2023-42125 | Hig | 0.51 | 7.8 | 0.00 | May 3, 2024 | Avast Premium Security Sandbox Protection Link Following Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Premium Security. An attacker must first obtain the ability to execute low-privileged… | ||
| CVE-2023-42099 | Hig | 0.51 | 7.8 | 0.00 | May 3, 2024 | Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Intel Driver & Support Assistant. An attacker must first obtain the ability to execute… | ||
| CVE-2023-32179 | Hig | 0.51 | 7.8 | 0.01 | May 3, 2024 | VIPRE Antivirus Plus FPQuarTransfer Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. An attacker must first obtain the ability to execute low-privileged… | ||
| CVE-2023-32178 | Hig | 0.51 | 7.8 | 0.01 | May 3, 2024 | VIPRE Antivirus Plus TelFileTransfer Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. An attacker must first obtain the ability to execute low-privileged… | ||
| CVE-2023-32175 | Hig | 0.51 | 7.8 | 0.01 | May 3, 2024 | VIPRE Antivirus Plus Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. An attacker must first obtain the ability to execute low-privileged code on the… | ||
| CVE-2023-27347 | Hig | 0.51 | 7.8 | 0.00 | May 3, 2024 | G DATA Total Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G Data Total Security. An attacker must first obtain the ability to execute low-privileged code on the… | ||
| CVE-2024-28907 | Hig | 0.51 | 7.8 | 0.01 | Apr 9, 2024 | Microsoft Brokering File System Elevation of Privilege Vulnerability | ||
| CVE-2024-21447 | Hig | 0.51 | 7.8 | 0.01 | Apr 9, 2024 | Windows Authentication Elevation of Privilege Vulnerability | ||
| CVE-2024-26199 | Hig | 0.51 | 7.8 | 0.01 | Mar 12, 2024 | Microsoft Office Elevation of Privilege Vulnerability | ||
| CVE-2023-42942 | Hig | 0.51 | 7.8 | 0.00 | Feb 21, 2024 | This issue was addressed with improved handling of symlinks. This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, tvOS 17.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.1. A malicious app may be able to gain root privileges. | ||
| CVE-2023-52338 | Hig | 0.51 | 7.8 | 0.00 | Jan 23, 2024 | A link following vulnerability in the Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to… | ||
| CVE-2023-52094 | Hig | 0.51 | 7.8 | 0.00 | Jan 23, 2024 | An updater link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to abuse the updater to delete an arbitrary folder, leading for a local privilege escalation on affected installations. Please note: an attacker must first obtain the… | ||
| CVE-2023-52092 | Hig | 0.51 | 7.8 | 0.00 | Jan 23, 2024 | A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit… | ||
| CVE-2023-52091 | Hig | 0.51 | 7.8 | 0.00 | Jan 23, 2024 | An anti-spyware engine link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to… | ||
| CVE-2023-52090 | Hig | 0.51 | 7.8 | 0.00 | Jan 23, 2024 | A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit… |
- risk 0.51cvss 7.8epss 0.01
Microsoft PLUGScheduler Scheduled Task Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of…
- risk 0.51cvss 7.8epss 0.01
Parallels Desktop Updater Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the…
- risk 0.51cvss 7.8epss 0.00
Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Intel Driver & Support Assistant. An attacker must first obtain the ability to execute…
- risk 0.51cvss 7.8epss 0.00
G DATA Total Security GDBackupSvc Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G Data Total Security. An attacker must first obtain the ability to execute…
- risk 0.51cvss 7.8epss 0.00
Avast Premium Security Sandbox Protection Link Following Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Premium Security. An attacker must first obtain the ability to execute low-privileged…
- risk 0.51cvss 7.8epss 0.00
Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Intel Driver & Support Assistant. An attacker must first obtain the ability to execute…
- risk 0.51cvss 7.8epss 0.01
VIPRE Antivirus Plus FPQuarTransfer Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. An attacker must first obtain the ability to execute low-privileged…
- risk 0.51cvss 7.8epss 0.01
VIPRE Antivirus Plus TelFileTransfer Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. An attacker must first obtain the ability to execute low-privileged…
- risk 0.51cvss 7.8epss 0.01
VIPRE Antivirus Plus Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Antivirus Plus. An attacker must first obtain the ability to execute low-privileged code on the…
- risk 0.51cvss 7.8epss 0.00
G DATA Total Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G Data Total Security. An attacker must first obtain the ability to execute low-privileged code on the…
- risk 0.51cvss 7.8epss 0.01
Microsoft Brokering File System Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Authentication Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
This issue was addressed with improved handling of symlinks. This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, tvOS 17.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.1. A malicious app may be able to gain root privileges.
- risk 0.51cvss 7.8epss 0.00
A link following vulnerability in the Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to…
- risk 0.51cvss 7.8epss 0.00
An updater link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to abuse the updater to delete an arbitrary folder, leading for a local privilege escalation on affected installations. Please note: an attacker must first obtain the…
- risk 0.51cvss 7.8epss 0.00
A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit…
- risk 0.51cvss 7.8epss 0.00
An anti-spyware engine link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to…
- risk 0.51cvss 7.8epss 0.00
A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit…