VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,754)

page 31 of 88
  • CVE-2024-38022HigJul 9, 2024
    risk 0.46cvss 7.0epss 0.01

    Windows Image Acquisition Elevation of Privilege Vulnerability

  • CVE-2024-35254HigJun 11, 2024
    risk 0.46cvss 7.1epss 0.01

    Azure Monitor Agent Elevation of Privilege Vulnerability

  • CVE-2024-5102HigJun 10, 2024
    risk 0.46cvss 7.0epss 0.00

    A sym-linked file accessed via the repair function in Avast Antivirus <24.2 on Windows may allow user to elevate privilege to delete arbitrary files or run processes as NT AUTHORITY\SYSTEM. The vulnerability exists within the "Repair" (settings -> troubleshooting -> repair)…

  • CVE-2024-30033HigMay 14, 2024
    risk 0.46cvss 7.0epss 0.01

    Windows Search Service Elevation of Privilege Vulnerability

  • CVE-2024-23459HigMay 2, 2024
    risk 0.46cvss 7.1epss 0.00

    An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Mac allows a system file to be overwritten.This issue affects Zscaler Client Connector on Mac : before 3.7.

  • CVE-2024-21432HigMar 12, 2024
    risk 0.46cvss 7.0epss 0.01

    Windows Update Stack Elevation of Privilege Vulnerability

  • CVE-2024-0206HigJan 9, 2024
    risk 0.46cvss 7.1epss 0.00

    A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to potentially gain an escalation of privileges. This was achieved by adding an entry to the registry under the Trellix ENS registry…

  • CVE-2023-36394HigNov 14, 2023
    risk 0.46cvss 7.0epss 0.07

    Windows Search Service Elevation of Privilege Vulnerability

  • CVE-2023-36046HigNov 14, 2023
    risk 0.46cvss 7.1epss 0.01

    Windows Authentication Denial of Service Vulnerability

  • CVE-2023-46654HigOct 25, 2023
    risk 0.46cvss 8.1epss 0.01

    Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the expected directory during the cleanup process of the 'CloudBees CD - Publish Artifact' post-build step, allowing attackers able to configure jobs to delete arbitrary files on the…

  • CVE-2023-36568HigOct 10, 2023
    risk 0.46cvss 7.0epss 0.00

    Microsoft Office Click-To-Run Elevation of Privilege Vulnerability

  • CVE-2023-36876HigAug 8, 2023
    risk 0.46cvss 7.1epss 0.01

    Reliability Analysis Metrics Calculation (RacTask) Elevation of Privilege Vulnerability

  • CVE-2023-35347HigJul 11, 2023
    risk 0.46cvss 7.1epss 0.01

    Microsoft Install Service Elevation of Privilege Vulnerability

  • CVE-2023-32050HigJul 11, 2023
    risk 0.46cvss 7.0epss 0.00

    Windows Installer Elevation of Privilege Vulnerability

  • CVE-2023-27469HigJun 30, 2023
    risk 0.46cvss 7.1epss 0.00

    Malwarebytes Anti-Exploit 4.4.0.220 is vulnerable to arbitrary file deletion and denial of service via an ALPC message in which FullFileNamePath lacks a '\0' character.

  • CVE-2023-24904HigMay 9, 2023
    risk 0.46cvss 7.1epss 0.01

    Windows Installer Elevation of Privilege Vulnerability

  • CVE-2022-34292HigApr 27, 2023
    risk 0.46cvss 7.1epss 0.00

    Docker Desktop for Windows before 4.6.0 allows attackers to overwrite any file through a symlink attack on the hyperv/create dockerBackendV2 API by controlling the DataFolder parameter for DockerDesktop.vhdx, a similar issue to CVE-2022-31647.

  • CVE-2022-31647HigApr 27, 2023
    risk 0.46cvss 7.1epss 0.00

    Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 API via a symlink in the DataFolder parameter, a different vulnerability than CVE-2022-26659.

  • CVE-2023-28222HigApr 11, 2023
    risk 0.46cvss 7.1epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2023-0652HigApr 6, 2023
    risk 0.46cvss 7.0epss 0.00

    Due to a hardlink created in the ProgramData folder during the repair process of the software, the installer (MSI) of WARP Client for Windows (<= 2022.12.582.0) allowed a malicious attacker to forge the destination of the hardlink and escalate privileges, overwriting SYSTEM…