VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,658)

page 18 of 83
  • CVE-2022-24671HigFeb 24, 2022
    risk 0.51cvss 7.8epss 0.00

    A link following privilege escalation vulnerability in Trend Micro Antivirus for Max 11.0.2150 and below could allow a local attacker to modify a file during the update process and escalate their privileges. Please note: an attacker must first obtain the ability to execute…

  • CVE-2021-44730HigFeb 17, 2022
    risk 0.51cvss 7.8epss 0.00

    snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this binary to another location to cause snap-confine to execute other arbitrary binaries and hence gain privilege escalation. Fixed in snapd versions 2.54.3+18.04,…

  • CVE-2022-21944HigJan 26, 2022
    risk 0.51cvss 7.8epss 0.00

    A UNIX Symbolic Link (Symlink) Following vulnerability in the systemd service file for watchman of openSUSE Backports SLE-15-SP3, Factory allows local attackers to escalate to root. This issue affects: openSUSE Backports SLE-15-SP3 watchman versions prior to 4.9.0. openSUSE…

  • CVE-2022-21895HigJan 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Windows User Profile Service Elevation of Privilege Vulnerability

  • CVE-2021-45231HigJan 10, 2022
    risk 0.51cvss 7.8epss 0.01

    A link following privilege escalation vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to create a specially crafted file with arbitrary content which could grant local…

  • CVE-2021-43238HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.01

    Windows Remote Access Elevation of Privilege Vulnerability

  • CVE-2021-43237HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.01

    Windows Setup Elevation of Privilege Vulnerability

  • CVE-2021-44038HigNov 19, 2021
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to escalate their privileges to root upon package installation or update.

  • CVE-2021-37969HigOct 8, 2021
    risk 0.51cvss 7.8epss 0.01

    Inappropriate implementation in Google Updater in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to perform local privilege escalation via a crafted file.

  • CVE-2021-34408HigSep 27, 2021
    risk 0.51cvss 7.8epss 0.00

    The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable directory as a privileged user during the installation or update of the client. This could allow for potential privilege escalation if a link was created between the…

  • CVE-2021-36744HigSep 6, 2021
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Security (Consumer) 2021 and 2020 are vulnerable to a directory junction vulnerability which could allow an attacker to exploit the system to escalate privileges and create a denial of service.

  • CVE-2021-26425HigAug 12, 2021
    risk 0.51cvss 7.8epss 0.01

    Windows Event Tracing Elevation of Privilege Vulnerability

  • CVE-2021-36983HigJul 30, 2021
    risk 0.51cvss 7.8epss 0.00

    replay-sorcery-kms in Replay Sorcery 0.6.0 allows a local attacker to gain root privileges via a symlink attack on /tmp/replay-sorcery or /tmp/replay-sorcery/device.sock.

  • CVE-2021-0094HigJun 9, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper link resolution before file access in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable an escalation of privilege via local access.

  • CVE-2021-31154HigMay 27, 2021
    risk 0.51cvss 7.8epss 0.00

    pleaseedit in please before 0.4 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack.

  • CVE-2020-15076HigMay 26, 2021
    risk 0.51cvss 7.8epss 0.00

    Private Tunnel installer for macOS version 3.0.1 and older versions may corrupt system critical files it should not have access via symlinks in /tmp.

  • CVE-2020-9452HigMay 25, 2021
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe includes functionality to quarantine files by copying a suspected ransomware file from one directory to another using SYSTEM privileges. Because unprivileged users have write permissions…

  • CVE-2021-23872HigMay 12, 2021
    risk 0.51cvss 7.8epss 0.00

    Privilege Escalation vulnerability in the File Lock component of McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated privileges by manipulating a symbolic link in the IOCTL interface.

  • CVE-2021-31187HigMay 11, 2021
    risk 0.51cvss 7.8epss 0.01

    Windows WalletService Elevation of Privilege Vulnerability

  • CVE-2020-28007HigMay 6, 2021
    risk 0.51cvss 7.8epss 0.01

    Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the log directory (owned by a non-root user), a symlink or hard link attack allows overwriting critical root-owned files anywhere on the filesystem.