VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,658)

page 20 of 83
  • CVE-2020-25776HigOct 2, 2020
    risk 0.51cvss 7.8epss 0.01

    Trend Micro Antivirus for Mac 2020 (Consumer) is vulnerable to a symbolic link privilege escalation attack where an attacker could exploit a critical file on the system to escalate their privileges. An attacker must first obtain the ability to execute low-privileged code on the…

  • CVE-2020-24562HigSep 29, 2020
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in Trend Micro OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to execute…

  • CVE-2020-17365HigSep 24, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an authorized user to potentially enable escalation of privilege via local access. The vulnerability allows a local user to corrupt system files: a local user can…

  • CVE-2020-6546HigSep 21, 2020
    risk 0.51cvss 7.8epss 0.00

    Inappropriate implementation in installer in Google Chrome prior to 84.0.4147.125 allowed a local attacker to potentially elevate privilege via a crafted filesystem.

  • CVE-2020-24955HigSep 1, 2020
    risk 0.51cvss 7.8epss 0.01

    SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivileged users to restore a malicious DLL from quarantine into the system32 folder via an NTFS directory junction, as demonstrated by a crafted ualapi.dll file that…

  • CVE-2020-24559HigSep 1, 2020
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services on macOS may allow an attacker to manipulate a certain binary to load and run a script from a user-writable folder, which then would allow them to execute…

  • CVE-2020-24556HigSep 1, 2020
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in Trend Micro Apex One, OfficeScan XG SP1, Worry-Free Business Security 10 SP1 and Worry-Free Business Security Services on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a…

  • CVE-2020-25031HigAug 31, 2020
    risk 0.51cvss 7.8epss 0.01

    checkinstall 1.6.2, when used to create a package that contains a symlink, may trigger the creation of a mode 0777 executable file.

  • CVE-2019-20383HigAug 13, 2020
    risk 0.51cvss 7.8epss 0.00

    ABBYY network license server in ABBYY FineReader 15 before Release 4 (aka 15.0.112.2130) allows escalation of privileges by local users via manipulations involving files and using symbolic links.

  • CVE-2020-11474HigJul 28, 2020
    risk 0.51cvss 7.8epss 0.01

    NCP Secure Enterprise Client before 10.15 r47589 allows a symbolic link attack on enumusb.reg via Support Assistant.

  • CVE-2020-6477HigMay 21, 2020
    risk 0.51cvss 7.8epss 0.00

    Inappropriate implementation in installer in Google Chrome on OS X prior to 83.0.4103.61 allowed a local attacker to perform privilege escalation via a crafted file.

  • CVE-2020-5837HigMay 11, 2020
    risk 0.51cvss 7.8epss 0.01

    Symantec Endpoint Protection, prior to 14.3, may not respect file permissions when writing to log files that are replaced by symbolic links, which can lead to a potential elevation of privilege.

  • CVE-2020-11446HigApr 29, 2020
    risk 0.51cvss 7.8epss 0.00

    ESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard links in some ESET directories and then force the product to write through these links into files that would normally not be write-able by the user, thus…

  • CVE-2020-12254HigApr 26, 2020
    risk 0.51cvss 7.8epss 0.00

    Avira Antivirus before 5.0.2003.1821 on Windows allows privilege escalation or a denial of service via abuse of a symlink.

  • CVE-2020-8948HigApr 15, 2020
    risk 0.51cvss 7.8epss 0.00

    The Sierra Wireless Windows Mobile Broadband Driver Packages (MBDP) before build 5043 allows an unprivileged user to overwrite arbitrary files in arbitrary folders using hard links. An unprivileged user could leverage this vulnerability to execute arbitrary code with system…

  • CVE-2020-1885HigApr 8, 2020
    risk 0.51cvss 7.8epss 0.00

    Writing to an unprivileged file from a privileged OVRRedir.exe process in Oculus Desktop before 1.44.0.32849 on Windows allows local users to write to arbitrary files and consequently gain privileges via vectors involving a hard link to a log file.

  • CVE-2012-1093HigFeb 21, 2020
    risk 0.51cvss 7.8epss 0.01

    The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during package installation.

  • CVE-2020-8950HigFeb 12, 2020
    risk 0.51cvss 7.8epss 0.01

    The AUEPLauncher service in Radeon AMD User Experience Program Launcher through 1.0.0.1 on Windows allows elevation of privilege by placing a crafted file in %PROGRAMDATA%\AMD\PPC\upload and then creating a symbolic link in %PROGRAMDATA%\AMD\PPC\temp that points to an arbitrary…

  • CVE-2019-16896HigDec 27, 2019
    risk 0.51cvss 7.8epss 0.00

    In K7 Ultimate Security 16.0.0117, the module K7BKCExt.dll (aka the backup module) improperly validates the administrative privileges of the user, allowing an arbitrary file write via a symbolic link attack with file restoration functionality.

  • CVE-2019-18232HigDec 11, 2019
    risk 0.51cvss 7.8epss 0.00

    SafeNet Sentinel LDK License Manager, all versions prior to 7.101(only Microsoft Windows versions are affected) is vulnerable when configured as a service. This vulnerability may allow an attacker with local access to create, write, and/or delete files in system folder using…