CWE-59
Improper Link Resolution Before File Access ('Link Following')
Description
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76
CVEs mapped to this weakness (1,658)
page 16 of 83| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-35320 | Hig | 0.51 | 7.8 | 0.00 | Jul 11, 2023 | Connected User Experiences and Telemetry Elevation of Privilege Vulnerability | ||
| CVE-2023-32056 | Hig | 0.51 | 7.8 | 0.01 | Jul 11, 2023 | Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability | ||
| CVE-2023-32053 | Hig | 0.51 | 7.8 | 0.00 | Jul 11, 2023 | Windows Installer Elevation of Privilege Vulnerability | ||
| CVE-2023-32012 | Hig | 0.51 | 7.8 | 0.01 | Jun 14, 2023 | Windows Container Manager Service Elevation of Privilege Vulnerability | ||
| CVE-2023-33865 | Hig | 0.51 | 7.8 | 0.01 | Jun 7, 2023 | RenderDoc before 1.27 allows local privilege escalation via a symlink attack. It relies on the /tmp/RenderDoc directory regardless of ownership. | ||
| CVE-2023-2939 | Hig | 0.51 | 7.8 | 0.00 | May 30, 2023 | Insufficient data validation in Installer in Google Chrome on Windows prior to 114.0.5735.90 allowed a local attacker to perform privilege escalation via crafted symbolic link. (Chromium security severity: Medium) | ||
| CVE-2023-27529 | Hig | 0.51 | 7.8 | 0.00 | May 25, 2023 | Wacom Tablet Driver installer prior to 6.4.2-1 (for macOS) contains an improper link resolution before file access vulnerability. When a user is tricked to execute a small malicious script before executing the affected version of the installer, arbitrary code may be executed… | ||
| CVE-2023-29343 | Hig | 0.51 | 7.8 | 0.02 | May 9, 2023 | SysInternals Sysmon for Windows Elevation of Privilege Vulnerability | ||
| CVE-2023-28892 | Hig | 0.51 | 7.8 | 0.00 | Mar 29, 2023 | Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:\AdwCleaner\Logs\AdwCleaner_Debug.log in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link. | ||
| CVE-2023-26088 | Hig | 0.51 | 7.8 | 0.00 | Mar 23, 2023 | In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the local quarantine system. It can also lead to privilege escalation in certain scenarios. | ||
| CVE-2023-24930 | Hig | 0.51 | 7.8 | 0.00 | Mar 14, 2023 | Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability | ||
| CVE-2023-25148 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2023 | A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to exploit the vulnerability by changing a specific file into a pseudo-symlink, allowing privilege escalation on affected installations. Please note: an attacker must first… | ||
| CVE-2023-25146 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2023 | A security agent link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to quarantine a file, delete the original folder and replace with a junction to an arbitrary location, ultimately leading to an arbitrary file dropped to an arbitrary… | ||
| CVE-2023-25145 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2023 | A link following vulnerability in the scanning function of Trend Micro Apex One agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in… | ||
| CVE-2022-45697 | Hig | 0.51 | 7.8 | 0.00 | Feb 27, 2023 | Arbitrary File Delete vulnerability in Razer Central before v7.8.0.381 when handling files in the Accounts directory. | ||
| CVE-2020-36657 | Hig | 0.51 | 7.8 | 0.00 | Jan 26, 2023 | uptimed before 0.4.6-r1 on Gentoo allows local users (with access to the uptimed user account) to gain root privileges by creating a hard link within the /var/spool/uptimed directory, because there is an unsafe chown -R call. | ||
| CVE-2023-21678 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | Windows Print Spooler Elevation of Privilege Vulnerability | ||
| CVE-2022-45798 | Hig | 0.51 | 7.8 | 0.00 | Dec 24, 2022 | A link following vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One as a Service could allow a local attacker to escalate privileges by creating a symbolic link and abusing the service to delete a file. Please note: an… | ||
| CVE-2022-44747 | Hig | 0.51 | 7.8 | 0.00 | Nov 7, 2022 | Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107. | ||
| CVE-2022-32905 | Hig | 0.51 | 7.8 | 0.00 | Nov 1, 2022 | This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13. Processing a maliciously crafted DMG file may lead to arbitrary code execution with system privileges. |
- risk 0.51cvss 7.8epss 0.00
Connected User Experiences and Telemetry Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Windows Installer Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Container Manager Service Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
RenderDoc before 1.27 allows local privilege escalation via a symlink attack. It relies on the /tmp/RenderDoc directory regardless of ownership.
- risk 0.51cvss 7.8epss 0.00
Insufficient data validation in Installer in Google Chrome on Windows prior to 114.0.5735.90 allowed a local attacker to perform privilege escalation via crafted symbolic link. (Chromium security severity: Medium)
- risk 0.51cvss 7.8epss 0.00
Wacom Tablet Driver installer prior to 6.4.2-1 (for macOS) contains an improper link resolution before file access vulnerability. When a user is tricked to execute a small malicious script before executing the affected version of the installer, arbitrary code may be executed…
- risk 0.51cvss 7.8epss 0.02
SysInternals Sysmon for Windows Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:\AdwCleaner\Logs\AdwCleaner_Debug.log in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link.
- risk 0.51cvss 7.8epss 0.00
In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the local quarantine system. It can also lead to privilege escalation in certain scenarios.
- risk 0.51cvss 7.8epss 0.00
Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to exploit the vulnerability by changing a specific file into a pseudo-symlink, allowing privilege escalation on affected installations. Please note: an attacker must first…
- risk 0.51cvss 7.8epss 0.00
A security agent link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to quarantine a file, delete the original folder and replace with a junction to an arbitrary location, ultimately leading to an arbitrary file dropped to an arbitrary…
- risk 0.51cvss 7.8epss 0.00
A link following vulnerability in the scanning function of Trend Micro Apex One agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in…
- risk 0.51cvss 7.8epss 0.00
Arbitrary File Delete vulnerability in Razer Central before v7.8.0.381 when handling files in the Accounts directory.
- risk 0.51cvss 7.8epss 0.00
uptimed before 0.4.6-r1 on Gentoo allows local users (with access to the uptimed user account) to gain root privileges by creating a hard link within the /var/spool/uptimed directory, because there is an unsafe chown -R call.
- risk 0.51cvss 7.8epss 0.01
Windows Print Spooler Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
A link following vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One as a Service could allow a local attacker to escalate privileges by creating a symbolic link and abusing the service to delete a file. Please note: an…
- risk 0.51cvss 7.8epss 0.00
Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107.
- risk 0.51cvss 7.8epss 0.00
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13. Processing a maliciously crafted DMG file may lead to arbitrary code execution with system privileges.