VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,658)

page 19 of 83
  • CVE-2021-28098HigApr 14, 2021
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Forescout CounterACT before 8.1.4. A local privilege escalation vulnerability is present in the logging function. SecureConnector runs with administrative privileges and writes logs entries to a file in %PROGRAMDATA%\ForeScout SecureConnector\ that has…

  • CVE-2021-28321HigApr 13, 2021
    risk 0.51cvss 7.8epss 0.01

    Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability

  • CVE-2021-30463HigApr 8, 2021
    risk 0.51cvss 7.8epss 0.01

    VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. After reading the RKEY value from user.conf under the /usr/local/vesta/data/users/admin directory, the admin password can be changed via a…

  • CVE-2020-7346HigMar 23, 2021
    risk 0.51cvss 7.8epss 0.00

    Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) for Windows prior to 11.6.100 allows a local, low privileged, attacker through the use of junctions to cause the product to load DLLs of the attacker's choosing. This requires the creation and removal of…

  • CVE-2021-26889HigMar 11, 2021
    risk 0.51cvss 7.8epss 0.01

    Windows Update Stack Elevation of Privilege Vulnerability

  • CVE-2021-26887HigMar 11, 2021
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists in Microsoft Windows when Folder redirection has been enabled via Group Policy. When folder redirection file server is co-located with Terminal server, an attacker who successfully exploited the vulnerability would be able to…

  • CVE-2021-3310HigMar 10, 2021
    risk 0.51cvss 7.8epss 0.01

    Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead to code execution and information disclosure (by reading local files).

  • CVE-2020-12878HigFeb 18, 2021
    risk 0.51cvss 7.8epss 0.01

    Digi ConnectPort X2e before 3.2.30.6 allows an attacker to escalate privileges from the python user to root via a symlink attack that uses chown, related to /etc/init.d/S50dropbear.sh and the /WEB/python/.ssh directory.

  • CVE-2021-26720HigFeb 17, 2021
    risk 0.51cvss 7.8epss 0.00

    avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on files under /run/avahi-daemon. NOTE:…

  • CVE-2021-23873HigFeb 10, 2021
    risk 0.51cvss 7.8epss 0.01

    Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and perform arbitrary file deletion as the SYSTEM user potentially causing Denial of Service via manipulating Junction link, after enumerating…

  • CVE-2021-21117HigFeb 9, 2021
    risk 0.51cvss 7.8epss 0.00

    Insufficient policy enforcement in Cryptohome in Google Chrome prior to 88.0.4324.96 allowed a local attacker to perform OS-level privilege escalation via a crafted file.

  • CVE-2021-23240HigJan 12, 2021
    risk 0.51cvss 7.8epss 0.01

    selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines…

  • CVE-2020-35766HigDec 28, 2020
    risk 0.51cvss 7.8epss 0.01

    The test suite in libopendkim in OpenDKIM through 2.10.3 allows local users to gain privileges via a symlink attack against the /tmp/testkeys file (related to t-testdata.h, t-setup.c, and t-cleanup.c). NOTE: this is applicable to persons who choose to engage in the "A number of…

  • CVE-2020-10003HigDec 8, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. A local attacker may be able to elevate their privileges.

  • CVE-2020-27697HigNov 18, 2020
    risk 0.51cvss 7.8epss 0.01

    Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a malicious DLL in a non-protected location with high privileges (symlink attack) which can lead to obtaining administrative privileges during the…

  • CVE-2020-23968HigNov 10, 2020
    risk 0.51cvss 7.8epss 0.01

    Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\Ilex\S&G\Logs\000-sngWSService1.log.

  • CVE-2020-16007HigNov 3, 2020
    risk 0.51cvss 7.8epss 0.00

    Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local attacker to potentially elevate privilege via a crafted filesystem.

  • CVE-2020-9901HigOct 22, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8. A local attacker may be able to elevate their privileges.

  • CVE-2020-9900HigOct 22, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A local attacker may be able to elevate their privileges.

  • CVE-2020-16939HigOct 16, 2020
    risk 0.51cvss 7.8epss 0.02

    An elevation of privilege vulnerability exists when Group Policy improperly checks access. An attacker who successfully exploited this vulnerability could run processes in an elevated context. To exploit the vulnerability, an attacker would first have to log on to the…