CWE-59
Improper Link Resolution Before File Access ('Link Following')
Description
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76
CVEs mapped to this weakness (1,658)
page 31 of 83| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-26426 | Hig | 0.46 | 7.0 | 0.01 | Aug 12, 2021 | Windows User Account Profile Picture Elevation of Privilege Vulnerability | ||
| CVE-2021-1092 | Hig | 0.46 | 7.1 | 0.00 | Jul 22, 2021 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the NVIDIA Control Panel application where it is susceptible to a Windows file system symbolic link attack where an unprivileged attacker can cause the applications to overwrite privileged files, resulting in… | ||
| CVE-2021-1091 | Hig | 0.46 | 7.1 | 0.00 | Jul 22, 2021 | NVIDIA GPU Display driver for Windows contains a vulnerability where an unprivileged user can create a file hard link that causes the driver to overwrite a file that requires elevated privilege to modify, which could lead to data loss or denial of service. | ||
| CVE-2020-27833 | Hig | 0.46 | 7.1 | 0.02 | May 14, 2021 | A Zip Slip vulnerability was found in the oc binary in openshift-clients where an arbitrary file write is achieved by using a specially crafted raw container image (.tar file) which contains symbolic links. The vulnerability is limited to the command `oc image extract`. If a… | ||
| CVE-2020-15075 | Hig | 0.46 | 7.1 | 0.00 | Mar 30, 2021 | OpenVPN Connect installer for macOS version 3.2.6 and older may corrupt system critical files it should not have access via symlinks in /tmp. | ||
| CVE-2021-26873 | Hig | 0.46 | 7.0 | 0.01 | Mar 11, 2021 | Windows User Profile Service Elevation of Privilege Vulnerability | ||
| CVE-2021-26866 | Hig | 0.46 | 7.1 | 0.01 | Mar 11, 2021 | Windows Update Service Elevation of Privilege Vulnerability | ||
| CVE-2021-26862 | Hig | 0.46 | 7.0 | 0.01 | Mar 11, 2021 | Windows Installer Elevation of Privilege Vulnerability | ||
| CVE-2020-28641 | Hig | 0.46 | 7.1 | 0.01 | Dec 22, 2020 | In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system. | ||
| CVE-2020-16853 | Hig | 0.46 | 7.1 | 0.01 | Sep 11, 2020 | An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status. To exploit this… | ||
| CVE-2020-16851 | Hig | 0.46 | 7.1 | 0.01 | Sep 11, 2020 | An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status. To exploit this… | ||
| CVE-2020-14990 | Hig | 0.46 | 7.1 | 0.01 | Jun 22, 2020 | IOBit Advanced SystemCare Free 13.5.0.263 allows local users to gain privileges for file deletion by manipulating the Clean & Optimize feature with an NTFS junction and an Object Manager symbolic link. | ||
| CVE-2020-8099 | Hig | 0.46 | 7.1 | 0.00 | Apr 21, 2020 | A vulnerability in the improper handling of junctions in Bitdefender Antivirus Free can allow an unprivileged user to substitute a quarantined file, and restore it to a privileged location. This issue affects: Bitdefender Antivirus Free versions prior to 1.0.17. | ||
| CVE-2020-0789 | Hig | 0.46 | 7.1 | 0.01 | Mar 12, 2020 | A denial of service vulnerability exists when the Visual Studio Extension Installer Service improperly handles hard links, aka 'Visual Studio Extension Installer Service Denial of Service Vulnerability'. | ||
| CVE-2020-5324 | Hig | 0.46 | 7.1 | 0.00 | Feb 21, 2020 | Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is limited to the Dell Firmware Update Utility during the time window while being executed by an administrator. During this time window, a locally authenticated… | ||
| CVE-2020-0730 | Hig | 0.46 | 7.1 | 0.01 | Feb 11, 2020 | An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'. | ||
| CVE-2019-18932 | Hig | 0.46 | 7.0 | 0.00 | Jan 21, 2020 | log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By default, it uses a fixed temporary directory /tmp/sarg. As the root user, sarg creates this directory or reuses an existing one in an insecure manner. An attacker can pre-create… | ||
| CVE-2019-19693 | Hig | 0.46 | 7.1 | 0.01 | Dec 20, 2019 | The Trend Micro Security 2020 consumer family of products contains a vulnerability that could allow a local attacker to disclose sensitive information or to create a denial-of-service condition on affected installations. An attacker must first obtain the ability to execute… | ||
| CVE-2019-18575 | Hig | 0.46 | 7.1 | 0.00 | Dec 6, 2019 | Dell Command Configure versions prior to 4.2.1 contain an uncontrolled search path vulnerability. A locally authenticated malicious user could exploit this vulnerability by creating a symlink to a target file, allowing the attacker to overwrite or corrupt a specified file on the… | ||
| CVE-2011-3632 | Hig | 0.46 | 7.1 | 0.00 | Nov 26, 2019 | Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks. |
- risk 0.46cvss 7.0epss 0.01
Windows User Account Profile Picture Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.00
NVIDIA GPU Display Driver for Windows contains a vulnerability in the NVIDIA Control Panel application where it is susceptible to a Windows file system symbolic link attack where an unprivileged attacker can cause the applications to overwrite privileged files, resulting in…
- risk 0.46cvss 7.1epss 0.00
NVIDIA GPU Display driver for Windows contains a vulnerability where an unprivileged user can create a file hard link that causes the driver to overwrite a file that requires elevated privilege to modify, which could lead to data loss or denial of service.
- risk 0.46cvss 7.1epss 0.02
A Zip Slip vulnerability was found in the oc binary in openshift-clients where an arbitrary file write is achieved by using a specially crafted raw container image (.tar file) which contains symbolic links. The vulnerability is limited to the command `oc image extract`. If a…
- risk 0.46cvss 7.1epss 0.00
OpenVPN Connect installer for macOS version 3.2.6 and older may corrupt system critical files it should not have access via symlinks in /tmp.
- risk 0.46cvss 7.0epss 0.01
Windows User Profile Service Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.01
Windows Update Service Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Installer Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.01
In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system.
- risk 0.46cvss 7.1epss 0.01
An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status. To exploit this…
- risk 0.46cvss 7.1epss 0.01
An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status. To exploit this…
- risk 0.46cvss 7.1epss 0.01
IOBit Advanced SystemCare Free 13.5.0.263 allows local users to gain privileges for file deletion by manipulating the Clean & Optimize feature with an NTFS junction and an Object Manager symbolic link.
- risk 0.46cvss 7.1epss 0.00
A vulnerability in the improper handling of junctions in Bitdefender Antivirus Free can allow an unprivileged user to substitute a quarantined file, and restore it to a privileged location. This issue affects: Bitdefender Antivirus Free versions prior to 1.0.17.
- risk 0.46cvss 7.1epss 0.01
A denial of service vulnerability exists when the Visual Studio Extension Installer Service improperly handles hard links, aka 'Visual Studio Extension Installer Service Denial of Service Vulnerability'.
- risk 0.46cvss 7.1epss 0.00
Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is limited to the Dell Firmware Update Utility during the time window while being executed by an administrator. During this time window, a locally authenticated…
- risk 0.46cvss 7.1epss 0.01
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.
- risk 0.46cvss 7.0epss 0.00
log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By default, it uses a fixed temporary directory /tmp/sarg. As the root user, sarg creates this directory or reuses an existing one in an insecure manner. An attacker can pre-create…
- risk 0.46cvss 7.1epss 0.01
The Trend Micro Security 2020 consumer family of products contains a vulnerability that could allow a local attacker to disclose sensitive information or to create a denial-of-service condition on affected installations. An attacker must first obtain the ability to execute…
- risk 0.46cvss 7.1epss 0.00
Dell Command Configure versions prior to 4.2.1 contain an uncontrolled search path vulnerability. A locally authenticated malicious user could exploit this vulnerability by creating a symlink to a target file, allowing the attacker to overwrite or corrupt a specified file on the…
- risk 0.46cvss 7.1epss 0.00
Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks.