VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,658)

page 34 of 83
  • CVE-2023-28141MedApr 18, 2023
    risk 0.44cvss 6.7epss 0.00

    An NTFS Junction condition exists in the Qualys Cloud Agent for Windows platform in versions before 4.8.0.31. Attackers may write files to arbitrary locations via a local attack vector. This allows attackers to assume the privileges of the process, and they may delete or…

  • CVE-2023-28972MedApr 17, 2023
    risk 0.44cvss 6.8epss 0.00

    An Improper Link Resolution Before File Access vulnerability in console port access of Juniper Networks Junos OS on NFX Series allows an attacker to bypass console access controls. When "set system ports console insecure" is enabled, root login is disallowed for Junos OS as…

  • CVE-2023-25940MedApr 4, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS version 9.5.0.0 contains improper link resolution before file access vulnerability in isi_gather_info. A high privileged local attacker could potentially exploit this vulnerability, leading to system takeover and it breaks the compliance mode guarantees.

  • CVE-2023-27850MedMar 10, 2023
    risk 0.44cvss 6.8epss 0.00

    NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that allows users with access to this feature to access arbitrary files on the device.

  • CVE-2009-1142MedNov 23, 2022
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can gain privileges via a symlink attack on /tmp files if vmware-user-suid-wrapper is setuid root and the ChmodChownDirectory function is enabled.

  • CVE-2022-41973HigOct 29, 2022
    risk 0.44cvss 7.8epss 0.01

    multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can change symlinks in multipathd due to incorrect symlink handling, which could lead to controlled…

  • CVE-2022-21770MedJul 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In sound driver, there is a possible information disclosure due to symlink following. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06558663; Issue ID: ALPS06558663.

  • CVE-2021-42056MedJun 24, 2022
    risk 0.44cvss 6.7epss 0.01

    Thales Safenet Authentication Client (SAC) for Linux and Windows through 10.7.7 creates insecure temporary hid and lock files allowing a local attacker, through a symlink attack, to overwrite arbitrary files, and potentially achieve arbitrary command execution with high…

  • CVE-2022-20085MedMay 3, 2022
    risk 0.44cvss 6.7epss 0.00

    In netdiag, there is a possible symbolic link following due to an improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06308877; Issue ID: ALPS06308877.

  • CVE-2022-20068MedApr 11, 2022
    risk 0.44cvss 6.7epss 0.00

    In mobile_log_d, there is a possible symbolic link following due to an improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06308907; Issue ID:…

  • CVE-2022-27815HigMar 30, 2022
    risk 0.44cvss 7.8epss 0.01

    SWHKD 1.1.5 unsafely uses the /tmp/swhkd.pid pathname. There can be an information leak or denial of service.

  • CVE-2022-20050MedMar 10, 2022
    risk 0.44cvss 6.7epss 0.00

    In connsyslogger, there is a possible symbolic link following due to improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06335038; Issue ID:…

  • CVE-2021-20153MedDec 30, 2021
    risk 0.44cvss 6.8epss 0.01

    Trendnet AC2600 TEW-827DRU version 2.08B01 contains a symlink vulnerability in the bittorrent functionality. If enabled, the bittorrent functionality is vulnerable to a symlink attack that could lead to remote code execution on the device. If an end user inserts a flash drive…

  • CVE-2021-26089MedJul 12, 2021
    risk 0.44cvss 6.7epss 0.00

    An improper symlink following in FortiClient for Mac 6.4.3 and below may allow an non-privileged user to execute arbitrary privileged shell commands during installation phase.

  • CVE-2021-31997MedJun 10, 2021
    risk 0.44cvss 6.8epss 0.00

    A UNIX Symbolic Link (Symlink) Following vulnerability in python-postorius of openSUSE Leap 15.2, Factory allows local attackers to escalate from users postorius or postorius-admin to root. This issue affects: openSUSE Leap 15.2 python-postorius version 1.3.2-lp152.1.2 and prior…

  • CVE-2020-10665MedMar 18, 2020
    risk 0.44cvss 6.7epss 0.01

    Docker Desktop allows local privilege escalation to NT AUTHORITY\SYSTEM because it mishandles the collection of diagnostics with Administrator privileges, leading to arbitrary DACL permissions overwrites and arbitrary file writes. This affects Docker Desktop Enterprise before…

  • CVE-2015-1869HigJan 14, 2020
    risk 0.44cvss 7.8epss 0.00

    The default event handling scripts in Automatic Bug Reporting Tool (ABRT) allow local users to gain privileges as demonstrated by a symlink attack on a var_log_messages file.

  • CVE-2019-10773HigDec 16, 2019
    risk 0.44cvss 7.8epss 0.02

    In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially crafted "bin" keys. Existing files could be overwritten depending on the current user permission set.

  • CVE-2019-3690MedDec 5, 2019
    risk 0.44cvss 6.8epss 0.00

    The chkstat tool in the permissions package followed symlinks before commit a9e1d26cd49ef9ee0c2060c859321128a6dd4230 (please also check the additional hardenings after this fix). This allowed local attackers with control over a path that is traversed by chkstat to escalate…

  • CVE-2019-12672MedSep 25, 2019
    risk 0.44cvss 6.8epss 0.01

    A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker with physical access to an affected device to execute arbitrary code on the underlying operating system (OS) with root privileges. The vulnerability is due to insufficient…