VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,658)

page 25 of 83
  • CVE-2026-41882HigApr 30, 2026
    risk 0.48cvss 7.4epss 0.00

    In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server

  • CVE-2026-33694HigApr 23, 2026
    risk 0.48cvss epss 0.00

    This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. As a result, this condition potentially facilitates arbitrary code execution, whereby an attacker may exploit the vulnerability to execute malicious code…

  • CVE-2026-40931HigApr 21, 2026
    risk 0.48cvss 8.4epss 0.00

    Compressing is a compressing and uncompressing lib for node. Prior to 2.1.1 and 1.10.5, the patch for CVE-2026-24884 relies on a purely logical string validation within the isPathWithinParent utility. This check verifies if a resolved path string starts with the destination…

  • CVE-2025-63946HigFeb 23, 2026
    risk 0.48cvss 7.4epss 0.00

    A privilege escalation (PE) vulnerability in the Tencent PC Manager app thru 17.10.28554.205 on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.

  • CVE-2025-63945HigFeb 23, 2026
    risk 0.48cvss 7.4epss 0.00

    A privilege escalation (PE) vulnerability in the Tencent iOA app thru 210.9.28693.621001 on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.

  • CVE-2026-24884HigFeb 4, 2026
    risk 0.48cvss 8.4epss 0.00

    Compressing is a compressing and uncompressing lib for node. In version 2.0.0 and 1.10.3 and prior, Compressing extracts TAR archives while restoring symbolic links without validating their targets. By embedding symlinks that resolve outside the intended extraction directory, an…

  • CVE-2025-21331HigJan 14, 2025
    risk 0.48cvss 7.3epss 0.01

    Windows Installer Elevation of Privilege Vulnerability

  • CVE-2024-49107HigDec 12, 2024
    risk 0.48cvss 7.3epss 0.02

    WmsRepair Service Elevation of Privilege Vulnerability

  • CVE-2024-43470HigSep 10, 2024
    risk 0.48cvss 7.3epss 0.01

    Azure Network Watcher VM Agent Elevation of Privilege Vulnerability

  • CVE-2024-38081HigJul 9, 2024
    risk 0.48cvss 7.3epss 0.01

    .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability

  • CVE-2024-30093HigJun 11, 2024
    risk 0.48cvss 7.3epss 0.01

    Windows Storage Elevation of Privilege Vulnerability

  • CVE-2024-26216HigApr 9, 2024
    risk 0.48cvss 7.3epss 0.01

    Windows File Server Resource Management Service Elevation of Privilege Vulnerability

  • CVE-2024-21329HigFeb 13, 2024
    risk 0.48cvss 7.3epss 0.01

    Azure Connected Machine Agent Elevation of Privilege Vulnerability

  • CVE-2023-35624HigDec 12, 2023
    risk 0.48cvss 7.3epss 0.01

    Azure Connected Machine Agent Elevation of Privilege Vulnerability

  • CVE-2023-25152HigFeb 8, 2023
    risk 0.48cvss 8.4epss 0.01

    Wings is Pterodactyl's server control plane. Affected versions are subject to a vulnerability which can be used to create new files and directory structures on the host system that previously did not exist, potentially allowing attackers to change their resource allocations,…

  • CVE-2021-41641HigJun 12, 2022
    risk 0.48cvss 8.4epss 0.00

    Deno <=1.14.0 file sandbox does not handle symbolic links correctly. When running Deno with specific write access, the Deno.symlink method can be used to gain access to any directory.

  • CVE-2022-27883HigApr 9, 2022
    risk 0.48cvss 7.3epss 0.01

    A link following vulnerability in Trend Micro Antivirus for Mac 11.5 could allow an attacker to create a specially-crafted file as a symlink that can lead to privilege escalation. Please note that an attacker must at least have low-level privileges on the system to attempt to…

  • CVE-2020-6012HigAug 4, 2020
    risk 0.48cvss 7.4epss 0.01

    ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sophisticated timed attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic…

  • CVE-2019-1317HigOct 10, 2019
    risk 0.48cvss 7.3epss 0.01

    A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'.

  • CVE-2018-1834HigNov 9, 2018
    risk 0.48cvss 7.4epss 0.00

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to escalate their privileges to root through a symbolic link attack. IBM X-Force ID: 150511.