CWE-59
Improper Link Resolution Before File Access ('Link Following')
Description
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76
CVEs mapped to this weakness (1,658)
page 18 of 83| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-24671 | Hig | 0.51 | 7.8 | 0.00 | Feb 24, 2022 | A link following privilege escalation vulnerability in Trend Micro Antivirus for Max 11.0.2150 and below could allow a local attacker to modify a file during the update process and escalate their privileges. Please note: an attacker must first obtain the ability to execute… | ||
| CVE-2021-44730 | Hig | 0.51 | 7.8 | 0.00 | Feb 17, 2022 | snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this binary to another location to cause snap-confine to execute other arbitrary binaries and hence gain privilege escalation. Fixed in snapd versions 2.54.3+18.04,… | ||
| CVE-2022-21944 | Hig | 0.51 | 7.8 | 0.00 | Jan 26, 2022 | A UNIX Symbolic Link (Symlink) Following vulnerability in the systemd service file for watchman of openSUSE Backports SLE-15-SP3, Factory allows local attackers to escalate to root. This issue affects: openSUSE Backports SLE-15-SP3 watchman versions prior to 4.9.0. openSUSE… | ||
| CVE-2022-21895 | Hig | 0.51 | 7.8 | 0.01 | Jan 11, 2022 | Windows User Profile Service Elevation of Privilege Vulnerability | ||
| CVE-2021-45231 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2022 | A link following privilege escalation vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to create a specially crafted file with arbitrary content which could grant local… | ||
| CVE-2021-43238 | Hig | 0.51 | 7.8 | 0.01 | Dec 15, 2021 | Windows Remote Access Elevation of Privilege Vulnerability | ||
| CVE-2021-43237 | Hig | 0.51 | 7.8 | 0.01 | Dec 15, 2021 | Windows Setup Elevation of Privilege Vulnerability | ||
| CVE-2021-44038 | Hig | 0.51 | 7.8 | 0.01 | Nov 19, 2021 | An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to escalate their privileges to root upon package installation or update. | ||
| CVE-2021-37969 | Hig | 0.51 | 7.8 | 0.01 | Oct 8, 2021 | Inappropriate implementation in Google Updater in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to perform local privilege escalation via a crafted file. | ||
| CVE-2021-34408 | Hig | 0.51 | 7.8 | 0.00 | Sep 27, 2021 | The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable directory as a privileged user during the installation or update of the client. This could allow for potential privilege escalation if a link was created between the… | ||
| CVE-2021-36744 | Hig | 0.51 | 7.8 | 0.00 | Sep 6, 2021 | Trend Micro Security (Consumer) 2021 and 2020 are vulnerable to a directory junction vulnerability which could allow an attacker to exploit the system to escalate privileges and create a denial of service. | ||
| CVE-2021-26425 | Hig | 0.51 | 7.8 | 0.01 | Aug 12, 2021 | Windows Event Tracing Elevation of Privilege Vulnerability | ||
| CVE-2021-36983 | Hig | 0.51 | 7.8 | 0.00 | Jul 30, 2021 | replay-sorcery-kms in Replay Sorcery 0.6.0 allows a local attacker to gain root privileges via a symlink attack on /tmp/replay-sorcery or /tmp/replay-sorcery/device.sock. | ||
| CVE-2021-0094 | Hig | 0.51 | 7.8 | 0.00 | Jun 9, 2021 | Improper link resolution before file access in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable an escalation of privilege via local access. | ||
| CVE-2021-31154 | Hig | 0.51 | 7.8 | 0.00 | May 27, 2021 | pleaseedit in please before 0.4 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack. | ||
| CVE-2020-15076 | Hig | 0.51 | 7.8 | 0.00 | May 26, 2021 | Private Tunnel installer for macOS version 3.0.1 and older versions may corrupt system critical files it should not have access via symlinks in /tmp. | ||
| CVE-2020-9452 | Hig | 0.51 | 7.8 | 0.00 | May 25, 2021 | An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe includes functionality to quarantine files by copying a suspected ransomware file from one directory to another using SYSTEM privileges. Because unprivileged users have write permissions… | ||
| CVE-2021-23872 | Hig | 0.51 | 7.8 | 0.00 | May 12, 2021 | Privilege Escalation vulnerability in the File Lock component of McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated privileges by manipulating a symbolic link in the IOCTL interface. | ||
| CVE-2021-31187 | Hig | 0.51 | 7.8 | 0.01 | May 11, 2021 | Windows WalletService Elevation of Privilege Vulnerability | ||
| CVE-2020-28007 | Hig | 0.51 | 7.8 | 0.01 | May 6, 2021 | Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the log directory (owned by a non-root user), a symlink or hard link attack allows overwriting critical root-owned files anywhere on the filesystem. |
- risk 0.51cvss 7.8epss 0.00
A link following privilege escalation vulnerability in Trend Micro Antivirus for Max 11.0.2150 and below could allow a local attacker to modify a file during the update process and escalate their privileges. Please note: an attacker must first obtain the ability to execute…
- risk 0.51cvss 7.8epss 0.00
snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this binary to another location to cause snap-confine to execute other arbitrary binaries and hence gain privilege escalation. Fixed in snapd versions 2.54.3+18.04,…
- risk 0.51cvss 7.8epss 0.00
A UNIX Symbolic Link (Symlink) Following vulnerability in the systemd service file for watchman of openSUSE Backports SLE-15-SP3, Factory allows local attackers to escalate to root. This issue affects: openSUSE Backports SLE-15-SP3 watchman versions prior to 4.9.0. openSUSE…
- risk 0.51cvss 7.8epss 0.01
Windows User Profile Service Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
A link following privilege escalation vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to create a specially crafted file with arbitrary content which could grant local…
- risk 0.51cvss 7.8epss 0.01
Windows Remote Access Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Setup Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to escalate their privileges to root upon package installation or update.
- risk 0.51cvss 7.8epss 0.01
Inappropriate implementation in Google Updater in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to perform local privilege escalation via a crafted file.
- risk 0.51cvss 7.8epss 0.00
The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable directory as a privileged user during the installation or update of the client. This could allow for potential privilege escalation if a link was created between the…
- risk 0.51cvss 7.8epss 0.00
Trend Micro Security (Consumer) 2021 and 2020 are vulnerable to a directory junction vulnerability which could allow an attacker to exploit the system to escalate privileges and create a denial of service.
- risk 0.51cvss 7.8epss 0.01
Windows Event Tracing Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
replay-sorcery-kms in Replay Sorcery 0.6.0 allows a local attacker to gain root privileges via a symlink attack on /tmp/replay-sorcery or /tmp/replay-sorcery/device.sock.
- risk 0.51cvss 7.8epss 0.00
Improper link resolution before file access in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable an escalation of privilege via local access.
- risk 0.51cvss 7.8epss 0.00
pleaseedit in please before 0.4 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack.
- risk 0.51cvss 7.8epss 0.00
Private Tunnel installer for macOS version 3.0.1 and older versions may corrupt system critical files it should not have access via symlinks in /tmp.
- risk 0.51cvss 7.8epss 0.00
An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe includes functionality to quarantine files by copying a suspected ransomware file from one directory to another using SYSTEM privileges. Because unprivileged users have write permissions…
- risk 0.51cvss 7.8epss 0.00
Privilege Escalation vulnerability in the File Lock component of McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated privileges by manipulating a symbolic link in the IOCTL interface.
- risk 0.51cvss 7.8epss 0.01
Windows WalletService Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the log directory (owned by a non-root user), a symlink or hard link attack allows overwriting critical root-owned files anywhere on the filesystem.