VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,754)

page 27 of 88
  • CVE-2020-6012HigAug 4, 2020
    risk 0.48cvss 7.4epss 0.01

    ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sophisticated timed attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic…

  • CVE-2019-1317HigOct 10, 2019
    risk 0.48cvss 7.3epss 0.01

    A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'.

  • CVE-2018-1834HigNov 9, 2018
    risk 0.48cvss 7.4epss 0.00

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to escalate their privileges to root through a symbolic link attack. IBM X-Force ID: 150511.

  • CVE-2024-14047HigSep 1, 2026
    risk 0.47cvss 7.2epss 0.00

    A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users. A low-privileged attacker with existing access to the system could pre-position malicious filesystem links, causing a subsequent elevated…

  • CVE-2026-11837HigJun 10, 2026
    risk 0.47cvss 7.3epss 0.00

    A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOLLOW when managing SSH authorized keys. An unprivileged local user can pre-stage…

  • CVE-2026-25906HigMar 3, 2026
    risk 0.47cvss 7.3epss 0.00

    Dell Optimizer, versions prior to 6.3.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

  • CVE-2025-12838HigDec 23, 2025
    risk 0.47cvss 7.3epss 0.00

    MSP360 Free Backup Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MSP360 Free Backup. An attacker must first obtain the ability to execute low-privileged code on the target…

  • CVE-2025-46637HigDec 9, 2025
    risk 0.47cvss 7.3epss 0.00

    Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A local malicious user could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2025-11578HigNov 10, 2025
    risk 0.47cvss 7.2epss 0.01

    A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise admin to gain root SSH access to the appliance by exploiting a symlink escape in pre-receive hook environments. By crafting a malicious repository and…

  • CVE-2025-55247HigOct 14, 2025
    risk 0.47cvss 7.3epss 0.01

    Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.

  • CVE-2025-8612HigAug 20, 2025
    risk 0.47cvss 7.3epss 0.00

    AOMEI Backupper Workstation Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of AOMEI Backupper Workstation. An attacker must first obtain the ability to execute low-privileged…

  • CVE-2025-5296HigAug 18, 2025
    risk 0.47cvss 7.3epss 0.00

    CWE-59: Improper Link Resolution Before File Access ('Link Following') vulnerability exists that could cause arbitrary data to be written to protected locations, potentially leading to escalation of privilege, arbitrary file corruption, exposure of application and system…

  • CVE-2025-36611HigJul 30, 2025
    risk 0.47cvss 7.3epss 0.00

    Dell Encryption and Dell Security Management Server, versions prior to 11.11.0, contain an Improper Link Resolution Before File Access ('Link Following') Vulnerability. A local malicious user could potentially exploit this vulnerability, leading to privilege escalation.

  • CVE-2025-49680HigJul 8, 2025
    risk 0.47cvss 7.3epss 0.00

    Improper link resolution before file access ('link following') in Windows Performance Recorder allows an authorized attacker to deny service locally.

  • CVE-2025-32721HigJun 10, 2025
    risk 0.47cvss 7.3epss 0.01

    Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-5474HigJun 6, 2025
    risk 0.47cvss 7.3epss 0.00

    2BrightSparks SyncBackFree Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of 2BrightSparks SyncBackFree. An attacker must first obtain the ability to execute low-privileged code…

  • CVE-2025-4211HigMay 16, 2025
    risk 0.47cvss —epss 0.00

    Improper Link Resolution Before File Access ('Link Following') vulnerability in QFileSystemEngine in the Qt corelib module on Windows which potentially allows Symlink Attacks and the use of Malicious Files. Issue originates from CVE-2024-38081. The vulnerability arises from the…

  • CVE-2025-23010HigApr 10, 2025
    risk 0.47cvss 7.2epss 0.00

    An Improper Link Resolution Before File Access ('Link Following') vulnerability in SonicWall NetExtender Windows (32 and 64 bit) client which allows an attacker to manipulate file paths.

  • CVE-2024-12753HigDec 30, 2024
    risk 0.47cvss 7.3epss 0.00

    Foxit PDF Reader Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system…

  • CVE-2024-22038HigNov 28, 2024
    risk 0.47cvss 7.3epss 0.00

    Various problems in obs-scm-bridge allows attackers that create specially crafted git repositories to leak information of cause denial of service.