VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,754)

page 36 of 88
  • CVE-2024-31952MedMay 14, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Magician 8.0.0 on macOS. Because symlinks are used during the installation process, an attacker can escalate privileges via arbitrary file permission writes. (The attacker must already have user privileges, and an administrator password must be…

  • CVE-2024-29188HigMar 24, 2024
    risk 0.44cvss 7.9epss 0.00

    WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The custom action behind WiX's `RemoveFolderEx` functionality could allow a standard user to delete protected directories. `RemoveFolderEx` deletes an entire directory tree…

  • CVE-2023-43116HigDec 22, 2023
    risk 0.44cvss 7.8epss 0.00

    A symbolic link following vulnerability in Buildkite Elastic CI for AWS versions prior to 6.7.1 and 5.22.5 allows the buildkite-agent user to change ownership of arbitrary directories via the PIPELINE_PATH variable in the fix-buildkite-agent-builds-permissions script.

  • CVE-2023-28065MedJun 23, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability leading to privilege escalation.

  • CVE-2023-28141MedApr 18, 2023
    risk 0.44cvss 6.7epss 0.00

    An NTFS Junction condition exists in the Qualys Cloud Agent for Windows platform in versions before 4.8.0.31. Attackers may write files to arbitrary locations via a local attack vector. This allows attackers to assume the privileges of the process, and they may delete or…

  • CVE-2023-28972MedApr 17, 2023
    risk 0.44cvss 6.8epss 0.00

    An Improper Link Resolution Before File Access vulnerability in console port access of Juniper Networks Junos OS on NFX Series allows an attacker to bypass console access controls. When "set system ports console insecure" is enabled, root login is disallowed for Junos OS as…

  • CVE-2023-25940MedApr 4, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS version 9.5.0.0 contains improper link resolution before file access vulnerability in isi_gather_info. A high privileged local attacker could potentially exploit this vulnerability, leading to system takeover and it breaks the compliance mode guarantees.

  • CVE-2023-27850MedMar 10, 2023
    risk 0.44cvss 6.8epss 0.00

    NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that allows users with access to this feature to access arbitrary files on the device.

  • CVE-2009-1142MedNov 23, 2022
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can gain privileges via a symlink attack on /tmp files if vmware-user-suid-wrapper is setuid root and the ChmodChownDirectory function is enabled.

  • CVE-2022-41973HigOct 29, 2022
    risk 0.44cvss 7.8epss 0.01

    multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can change symlinks in multipathd due to incorrect symlink handling, which could lead to controlled…

  • CVE-2022-21770MedJul 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In sound driver, there is a possible information disclosure due to symlink following. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06558663; Issue ID: ALPS06558663.

  • CVE-2021-42056MedJun 24, 2022
    risk 0.44cvss 6.7epss 0.01

    Thales Safenet Authentication Client (SAC) for Linux and Windows through 10.7.7 creates insecure temporary hid and lock files allowing a local attacker, through a symlink attack, to overwrite arbitrary files, and potentially achieve arbitrary command execution with high…

  • CVE-2022-20085MedMay 3, 2022
    risk 0.44cvss 6.7epss 0.00

    In netdiag, there is a possible symbolic link following due to an improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06308877; Issue ID: ALPS06308877.

  • CVE-2022-20068MedApr 11, 2022
    risk 0.44cvss 6.7epss 0.00

    In mobile_log_d, there is a possible symbolic link following due to an improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06308907; Issue ID:…

  • CVE-2022-27815HigMar 30, 2022
    risk 0.44cvss 7.8epss 0.01

    SWHKD 1.1.5 unsafely uses the /tmp/swhkd.pid pathname. There can be an information leak or denial of service.

  • CVE-2022-20050MedMar 10, 2022
    risk 0.44cvss 6.7epss 0.00

    In connsyslogger, there is a possible symbolic link following due to improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06335038; Issue ID:…

  • CVE-2021-20153MedDec 30, 2021
    risk 0.44cvss 6.8epss 0.01

    Trendnet AC2600 TEW-827DRU version 2.08B01 contains a symlink vulnerability in the bittorrent functionality. If enabled, the bittorrent functionality is vulnerable to a symlink attack that could lead to remote code execution on the device. If an end user inserts a flash drive…

  • CVE-2021-26089MedJul 12, 2021
    risk 0.44cvss 6.7epss 0.00

    An improper symlink following in FortiClient for Mac 6.4.3 and below may allow an non-privileged user to execute arbitrary privileged shell commands during installation phase.

  • CVE-2021-31997MedJun 10, 2021
    risk 0.44cvss 6.8epss 0.00

    A UNIX Symbolic Link (Symlink) Following vulnerability in python-postorius of openSUSE Leap 15.2, Factory allows local attackers to escalate from users postorius or postorius-admin to root. This issue affects: openSUSE Leap 15.2 python-postorius version 1.3.2-lp152.1.2 and prior…

  • CVE-2020-10665MedMar 18, 2020
    risk 0.44cvss 6.7epss 0.01

    Docker Desktop allows local privilege escalation to NT AUTHORITY\SYSTEM because it mishandles the collection of diagnostics with Administrator privileges, leading to arbitrary DACL permissions overwrites and arbitrary file writes. This affects Docker Desktop Enterprise before…