VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,754)

page 42 of 88
  • CVE-2024-27885MedJun 10, 2024
    risk 0.41cvss 6.3epss 0.00

    This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7. An app may be able to modify protected parts of the file system.

  • CVE-2023-32454MedFeb 6, 2024
    risk 0.41cvss 6.3epss 0.00

    DUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerability. A local malicious standard user could exploit the vulnerability to create arbitrary files, leading to denial of service

  • CVE-2023-28797MedOct 23, 2023
    risk 0.41cvss 6.3epss 0.00

    Zscaler Client Connector for Windows before 4.1 writes/deletes a configuration file inside specific folders on the disk. A malicious user can replace the folder and execute code as a privileged user.

  • CVE-2023-28071MedJun 23, 2023
    risk 0.41cvss 6.3epss 0.00

    Dell Command | Update, Dell Update, and Alienware Update versions 4.9.0, A01 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability to create arbitrary folder leading to…

  • CVE-2022-38730MedApr 27, 2023
    risk 0.41cvss 6.3epss 0.00

    Docker Desktop for Windows before 4.6 allows attackers to overwrite any file through the windowscontainers/start dockerBackendV2 API by controlling the data-root field inside the DaemonJSON field in the WindowsContainerStartRequest class. This allows exploiting a symlink…

  • CVE-2023-23558MedFeb 16, 2023
    risk 0.41cvss 6.3epss 0.00

    In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sentry-native-etserver with mode 0777 before the etserver process is started. The attacker can choose to read sensitive information from that file, or modify the…

  • CVE-2023-21725MedJan 10, 2023
    risk 0.41cvss 6.3epss 0.00

    Windows Malicious Software Removal Tool Elevation of Privilege Vulnerability

  • CVE-2021-20197MedMar 26, 2021
    risk 0.41cvss 6.3epss 0.00

    There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an…

  • CVE-2020-3237MedJun 3, 2020
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in the Cisco Application Framework component of the Cisco IOx application environment could allow an authenticated, local attacker to overwrite arbitrary files in the virtual instance that is running on the affected device. The vulnerability is due to…

  • CVE-2013-1429MedNov 7, 2019
    risk 0.41cvss 6.3epss 0.01

    Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks.

  • CVE-2019-1053MedJun 12, 2019
    risk 0.41cvss 6.3epss 0.01

    An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker who successfully exploited the vulnerability could elevate privileges by escaping a sandbox. To exploit this vulnerability, an attacker would require…

  • CVE-2019-0986MedJun 12, 2019
    risk 0.41cvss 6.3epss 0.02

    An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context. To exploit this vulnerability, an attacker…

  • CVE-2026-81690HigAug 27, 2026
    risk 0.40cvss 7.3epss 0.00

    openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file allowlist scan. The scan enumerated the drive with rglob(), which in CPython does not descend into symlinked directories and treats the symlink as an ordinary directory,…

  • CVE-2026-39243MedJul 9, 2026
    risk 0.40cvss 5.5epss 0.00

    decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and file corruption. When processing hardlink entries (type === 'link'), the x.linkname field from the archive is passed directly to fs.link() without validation…

  • CVE-2026-56236MedJun 21, 2026
    risk 0.40cvss 6.1epss 0.00

    Capgo CLI before 12.128.2 contains arbitrary file overwrite vulnerabilities in login and build credentials operations that follow symlinks without validation. Attackers can create malicious symlinks in repositories to overwrite arbitrary files or expose credentials with…

  • CVE-2026-47833MedJun 18, 2026
    risk 0.40cvss 6.1epss 0.00

    setupBpmLogs follows symlink for bpm.log open and chown — container-to-host privilege escalation via /etc/shadow. A compromised process inside a bpm container can cause root to chown an arbitrary host file to vcap and append bpm JSON log lines to it. The chown alone lets the…

  • CVE-2026-45384MedJun 10, 2026
    risk 0.40cvss 6.1epss 0.00

    bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.12, there is an arbitrary file overwrite vulnerability via symlink attack on predictable temp files during archive update. This issue has been patched in…

  • CVE-2026-45491MedJun 9, 2026
    risk 0.40cvss 6.2epss 0.00

    Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.

  • CVE-2026-35338HigApr 22, 2026
    risk 0.40cvss 7.3epss 0.00

    A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. The implementation only validates if the target path is literally / and does not canonicalize the path. An attacker or accidental user can use path variants such…

  • CVE-2026-28866MedMar 25, 2026
    risk 0.40cvss 6.2epss 0.00

    This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.