VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,658)

page 44 of 83
  • CVE-2025-59510MedNov 11, 2025
    risk 0.36cvss 5.5epss 0.01

    Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service locally.

  • CVE-2025-12418MedNov 7, 2025
    risk 0.36cvss epss 0.00

    Potential Denial of Service issue in all supported versions of Revenera InstallShield version 2025 R1, 2024 R2, 2023 R2, and prior. When e.g., a local administrator performs an uninstall, a symlink may get followed on removal of a user writeable configuration directory and…

  • CVE-2025-43446MedNov 4, 2025
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to modify protected parts of the file system.

  • CVE-2025-43394MedNov 4, 2025
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access protected user data.

  • CVE-2025-43379MedNov 4, 2025
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. An app may be able to access protected user data.

  • CVE-2025-43288MedNov 4, 2025
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to bypass Privacy preferences.

  • CVE-2024-54554MedAug 29, 2025
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be able to access sensitive user data.

  • CVE-2025-30642MedJun 17, 2025
    risk 0.36cvss 5.5epss 0.00

    A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to create a denial of service (DoS) situation on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target…

  • CVE-2025-0913MedJun 11, 2025
    risk 0.36cvss 5.5epss 0.00

    os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when the target path was a symlink to a nonexistent…

  • CVE-2025-31198MedMay 29, 2025
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A path handling issue was addressed with improved validation.

  • CVE-2025-29837MedMay 13, 2025
    risk 0.36cvss 5.5epss 0.01

    Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally.

  • CVE-2025-24278MedMar 31, 2025
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access protected user data.

  • CVE-2020-3432MedFeb 12, 2025
    risk 0.36cvss 5.6epss 0.00

    A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS could allow an authenticated, local attacker to corrupt the content of any file in the filesystem. The vulnerability is due to the incorrect handling of directory paths. An…

  • CVE-2025-24104MedJan 27, 2025
    risk 0.36cvss 5.5epss 0.01

    This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4. Restoring a maliciously crafted backup file may lead to modification of protected system files.

  • CVE-2025-24103MedJan 27, 2025
    risk 0.36cvss 5.5epss 0.01

    This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to access protected user data.

  • CVE-2025-21274MedJan 14, 2025
    risk 0.36cvss 5.5epss 0.01

    Windows Event Tracing Denial of Service Vulnerability

  • CVE-2024-12754MedDec 30, 2024
    risk 0.36cvss 5.5epss 0.01

    AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order…

  • CVE-2024-44211MedDec 20, 2024
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be able to access user-sensitive data.

  • CVE-2024-7236MedNov 22, 2024
    risk 0.36cvss 5.5epss 0.00

    AVG AntiVirus Free icarus Arbitrary File Creation Denial of Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AVG AntiVirus Free. An attacker must first obtain the ability to execute…

  • CVE-2024-7235MedNov 22, 2024
    risk 0.36cvss 5.5epss 0.00

    AVG AntiVirus Free Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AVG AntiVirus Free. An attacker must first obtain the ability to execute low-privileged code on the…