VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,658)

page 30 of 83
  • CVE-2022-31647HigApr 27, 2023
    risk 0.46cvss 7.1epss 0.00

    Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 API via a symlink in the DataFolder parameter, a different vulnerability than CVE-2022-26659.

  • CVE-2023-28222HigApr 11, 2023
    risk 0.46cvss 7.1epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2023-0652HigApr 6, 2023
    risk 0.46cvss 7.0epss 0.00

    Due to a hardlink created in the ProgramData folder during the repair process of the software, the installer (MSI) of WARP Client for Windows (<= 2022.12.582.0) allowed a malicious attacker to forge the destination of the hardlink and escalate privileges, overwriting SYSTEM…

  • CVE-2023-1412HigApr 5, 2023
    risk 0.46cvss 7.0epss 0.00

    An unprivileged (non-admin) user can exploit an Improper Access Control vulnerability in the Cloudflare WARP Client for Windows (<= 2022.12.582.0) to perform privileged operations with SYSTEM context by working with a combination of opportunistic locks (oplock) and symbolic…

  • CVE-2023-21760HigJan 10, 2023
    risk 0.46cvss 7.1epss 0.01

    Windows Print Spooler Elevation of Privilege Vulnerability

  • CVE-2023-21542HigJan 10, 2023
    risk 0.46cvss 7.0epss 0.00

    Windows Installer Elevation of Privilege Vulnerability

  • CVE-2009-1143HigNov 23, 2022
    risk 0.46cvss 7.0epss 0.00

    An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended access restrictions on mounting shares via a symlink attack that leverages a realpath race condition in mount.vmhgfs (aka hgfsmounter).

  • CVE-2022-31250HigJul 20, 2022
    risk 0.46cvss 7.1epss 0.00

    A UNIX Symbolic Link (Symlink) Following vulnerability in keylime of openSUSE Tumbleweed allows local attackers to escalate from the keylime user to root. This issue affects: openSUSE Tumbleweed keylime versions prior to 6.4.2-1.1.

  • CVE-2022-32450HigJul 18, 2022
    risk 0.46cvss 7.1epss 0.01

    AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder (used for ad.trace and chat) but the product runs as SYSTEM when writing chat-room data there.

  • CVE-2022-30687HigMay 27, 2022
    risk 0.46cvss 7.1epss 0.00

    Trend Micro Maximum Security 2022 is vulnerable to a link following vulnerability that could allow a low privileged local user to manipulate the product's secure erase feature to delete arbitrary files.

  • CVE-2022-26659HigMar 25, 2022
    risk 0.46cvss 7.1epss 0.00

    Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink in place of where the installer writes its log file. Starting from version 4.6.0, the Docker Desktop installer, when run elevated,…

  • CVE-2022-0017HigFeb 10, 2022
    risk 0.46cvss 7.0epss 0.00

    An improper link resolution before file access ('link following') vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that enables a local attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges under certain…

  • CVE-2022-21997HigFeb 9, 2022
    risk 0.46cvss 7.1epss 0.01

    Windows Print Spooler Elevation of Privilege Vulnerability

  • CVE-2021-45442HigJan 10, 2022
    risk 0.46cvss 7.1epss 0.00

    A link following denial-of-service vulnerability in Trend Micro Worry-Free Business Security (on prem only) could allow a local attacker to overwrite arbitrary files in the context of SYSTEM. This is similar to, but not the same as CVE-2021-44024. Please note: an attacker must…

  • CVE-2021-44024HigJan 10, 2022
    risk 0.46cvss 7.1epss 0.00

    A link following denial-of-service vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to overwrite arbitrary files in the context of SYSTEM. Please note: an attacker must…

  • CVE-2021-44023HigDec 16, 2021
    risk 0.46cvss 7.1epss 0.00

    A link following denial-of-service (DoS) vulnerability in the Trend Micro Security (Consumer) 2021 familiy of products could allow an attacker to abuse the PC Health Checkup feature of the product to create symlinks that would allow modification of files which could lead to a…

  • CVE-2021-41057HigNov 14, 2021
    risk 0.46cvss 7.1epss 0.00

    In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.

  • CVE-2021-21686HigNov 4, 2021
    risk 0.46cvss 8.1epss 0.02

    File path filters in the agent-to-controller security subsystem of Jenkins 2.318 and earlier, LTS 2.303.2 and earlier do not canonicalize paths, allowing operations to follow symbolic links to outside allowed directories.

  • CVE-2021-36286HigSep 28, 2021
    risk 0.46cvss 7.1epss 0.00

    Dell SupportAssist Client Consumer versions 3.9.13.0 and any versions prior to 3.9.13.0 contain an arbitrary file deletion vulnerability that can be exploited by using the Windows feature of NTFS called Symbolic links. Symbolic links can be created by any(non-privileged) user…

  • CVE-2021-37712HigAug 31, 2021
    risk 0.46cvss 8.2epss 0.02

    The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This…