CWE-59
Improper Link Resolution Before File Access ('Link Following')
Description
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76
CVEs mapped to this weakness (1,658)
page 15 of 83| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-47192 | Hig | 0.51 | 7.8 | 0.00 | Jan 23, 2024 | An agent link vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit… | ||
| CVE-2023-42137 | Hig | 0.51 | 7.8 | 0.00 | Jan 15, 2024 | PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privileges by using malicious symlinks. The attacker must have shell access to the device in order to exploit this vulnerability. | ||
| CVE-2024-20656 | Hig | 0.51 | 7.8 | 0.04 | Jan 9, 2024 | Visual Studio Elevation of Privilege Vulnerability | ||
| CVE-2023-36391 | Hig | 0.51 | 7.8 | 0.07 | Dec 12, 2023 | Local Security Authority Subsystem Service Elevation of Privilege Vulnerability | ||
| CVE-2023-35633 | Hig | 0.51 | 7.8 | 0.09 | Dec 12, 2023 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2023-43590 | Hig | 0.51 | 7.8 | 0.00 | Nov 15, 2023 | Link following in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation of privilege via local access. | ||
| CVE-2023-36705 | Hig | 0.51 | 7.8 | 0.01 | Nov 14, 2023 | Windows Installer Elevation of Privilege Vulnerability | ||
| CVE-2023-36047 | Hig | 0.51 | 7.8 | 0.01 | Nov 14, 2023 | Windows Authentication Elevation of Privilege Vulnerability | ||
| CVE-2023-36737 | Hig | 0.51 | 7.8 | 0.01 | Oct 10, 2023 | Azure Network Watcher VM Agent Elevation of Privilege Vulnerability | ||
| CVE-2023-36723 | Hig | 0.51 | 7.8 | 0.02 | Oct 10, 2023 | Windows Container Manager Service Elevation of Privilege Vulnerability | ||
| CVE-2023-36711 | Hig | 0.51 | 7.8 | 0.01 | Oct 10, 2023 | Windows Runtime C++ Template Library Elevation of Privilege Vulnerability | ||
| CVE-2023-36758 | Hig | 0.51 | 7.8 | 0.01 | Sep 12, 2023 | Visual Studio Elevation of Privilege Vulnerability | ||
| CVE-2023-32163 | Hig | 0.51 | 7.8 | 0.00 | Sep 6, 2023 | Wacom Drivers for Windows Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Wacom Drivers for Windows. An attacker must first obtain the ability to execute low-privileged code on… | ||
| CVE-2022-46869 | Hig | 0.51 | 7.8 | 0.00 | Aug 31, 2023 | Local privilege escalation during installation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40278, Acronis True Image OEM (Windows) before build 42575. | ||
| CVE-2019-13689 | Hig | 0.51 | 7.8 | 0.00 | Aug 25, 2023 | Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform arbitrary read/write via a malicious file. (Chromium security severity: Critical) | ||
| CVE-2023-38175 | Hig | 0.51 | 7.8 | 0.01 | Aug 8, 2023 | Microsoft Windows Defender Elevation of Privilege Vulnerability | ||
| CVE-2023-36903 | Hig | 0.51 | 7.8 | 0.02 | Aug 8, 2023 | Windows System Assessment Tool Elevation of Privilege Vulnerability | ||
| CVE-2023-35379 | Hig | 0.51 | 7.8 | 0.01 | Aug 8, 2023 | Reliability Analysis Metrics Calculation Engine (RACEng) Elevation of Privilege Vulnerability | ||
| CVE-2023-35353 | Hig | 0.51 | 7.8 | 0.01 | Jul 11, 2023 | Connected User Experiences and Telemetry Elevation of Privilege Vulnerability | ||
| CVE-2023-35342 | Hig | 0.51 | 7.8 | 0.00 | Jul 11, 2023 | Windows Image Acquisition Elevation of Privilege Vulnerability |
- risk 0.51cvss 7.8epss 0.00
An agent link vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit…
- risk 0.51cvss 7.8epss 0.00
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privileges by using malicious symlinks. The attacker must have shell access to the device in order to exploit this vulnerability.
- risk 0.51cvss 7.8epss 0.04
Visual Studio Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.07
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.09
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Link following in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation of privilege via local access.
- risk 0.51cvss 7.8epss 0.01
Windows Installer Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Authentication Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Azure Network Watcher VM Agent Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.02
Windows Container Manager Service Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Runtime C++ Template Library Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Visual Studio Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Wacom Drivers for Windows Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Wacom Drivers for Windows. An attacker must first obtain the ability to execute low-privileged code on…
- risk 0.51cvss 7.8epss 0.00
Local privilege escalation during installation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40278, Acronis True Image OEM (Windows) before build 42575.
- risk 0.51cvss 7.8epss 0.00
Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform arbitrary read/write via a malicious file. (Chromium security severity: Critical)
- risk 0.51cvss 7.8epss 0.01
Microsoft Windows Defender Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.02
Windows System Assessment Tool Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Reliability Analysis Metrics Calculation Engine (RACEng) Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Connected User Experiences and Telemetry Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Windows Image Acquisition Elevation of Privilege Vulnerability