VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,658)

page 45 of 83
  • CVE-2024-7228MedNov 22, 2024
    risk 0.36cvss 5.5epss 0.00

    Avast Free Antivirus Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Avast Free Antivirus. An attacker must first obtain the ability to execute low-privileged code on…

  • CVE-2024-44273MedOct 28, 2024
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. A malicious app may be able to access private information.

  • CVE-2024-44264MedOct 28, 2024
    risk 0.36cvss 5.5epss 0.01

    This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious app may be able to create symlinks to protected regions of the disk.

  • CVE-2024-44175MedOct 28, 2024
    risk 0.36cvss 5.5epss 0.01

    This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7.1. An app may be able to access sensitive user data.

  • CVE-2024-45315MedOct 11, 2024
    risk 0.36cvss 5.5epss 0.00

    The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard privileges to create arbitrary folders and files, potentially leading to local Denial of…

  • CVE-2024-43603MedOct 8, 2024
    risk 0.36cvss 5.5epss 0.01

    Visual Studio Collector Service Denial of Service Vulnerability

  • CVE-2024-44178MedSep 17, 2024
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An app may be able to modify protected parts of the file system.

  • CVE-2024-44131MedSep 17, 2024
    risk 0.36cvss 5.5epss 0.01

    This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to access sensitive user data.

  • CVE-2024-30065MedJun 11, 2024
    risk 0.36cvss 5.5epss 0.01

    Windows Themes Denial of Service Vulnerability

  • CVE-2024-23285MedMar 8, 2024
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma 14.4. An app may be able to create symlinks to protected regions of the disk.

  • CVE-2024-0068MedFeb 29, 2024
    risk 0.36cvss 5.5epss 0.00

    Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows File Manipulation.This issue affects Workforce Access: before 8.7.1.

  • CVE-2023-51654MedDec 26, 2023
    risk 0.36cvss 5.5epss 0.00

    Improper link resolution before file access ('Link Following') issue exists in iPrint&Scan Desktop for Windows versions 11.0.0 and earlier. A symlink attack by a malicious user may cause a Denial-of-service (DoS) condition on the PC.

  • CVE-2023-41968MedSep 27, 2023
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to read arbitrary files.

  • CVE-2023-32556MedJun 26, 2023
    risk 0.36cvss 5.5epss 0.00

    A link following vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to disclose sensitive information. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to…

  • CVE-2023-24577MedMar 13, 2023
    risk 0.36cvss 5.5epss 0.00

    McAfee Total Protection prior to 16.0.50 allows attackers to elevate user privileges due to Improper Link Resolution via registry keys. This could enable a user with lower privileges to execute unauthorized tasks.

  • CVE-2023-21567MedFeb 14, 2023
    risk 0.36cvss 5.6epss 0.01

    Visual Studio Denial of Service Vulnerability

  • CVE-2022-39253MedOct 19, 2022
    risk 0.36cvss 5.5epss 0.01

    Git is an open source, scalable, distributed revision control system. Versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4 are subject to exposure of sensitive information to a malicious actor. When performing a local clone (where the source and…

  • CVE-2022-0029MedSep 14, 2022
    risk 0.36cvss 5.5epss 0.00

    An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local attacker to read files on the system with elevated privileges when generating a tech support file.

  • CVE-2022-35631MedJul 29, 2022
    risk 0.36cvss 5.5epss 0.00

    On MacOS and Linux, it may be possible to perform a symlink attack by replacing this predictable file name with a symlink to another file and have the Velociraptor client overwrite the other file. This issue was resolved in Velociraptor 0.6.5-2.

  • CVE-2022-20720MedApr 15, 2022
    risk 0.36cvss 5.5epss 0.01

    Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install…