VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,658)

page 46 of 83
  • CVE-2022-21838MedJan 11, 2022
    risk 0.36cvss 5.5epss 0.01

    Windows Cleanup Manager Elevation of Privilege Vulnerability

  • CVE-2021-1612MedSep 23, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to overwrite arbitrary files on the local system. This vulnerability is due to improper access controls on files within the local file system. An attacker could exploit this…

  • CVE-2021-30968MedAug 24, 2021
    risk 0.36cvss 5.5epss 0.01

    A validation issue related to hard link behavior was addressed with improved sandbox restrictions. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. A malicious application may…

  • CVE-2021-30855MedAug 24, 2021
    risk 0.36cvss 5.5epss 0.02

    A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, iOS 15 and iPadOS 15, watchOS 8, macOS Big Sur 11.6. An application may be…

  • CVE-2021-27851MedApr 26, 2021
    risk 0.36cvss 5.5epss 0.00

    A security vulnerability that can lead to local privilege escalation has been found in ’guix-daemon’. It affects multi-user setups in which ’guix-daemon’ runs locally. The attack consists in having an unprivileged user spawn a build process, for instance with `guix…

  • CVE-2020-4717MedMar 10, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability exists in IBM SPSS Modeler Subscription Installer that allows a user with create symbolic link permission to write arbitrary file in another protected path during product installation. IBM X-Force ID: 187727.

  • CVE-2021-24084MedFeb 25, 2021
    risk 0.36cvss 5.5epss 0.03

    Windows Mobile Device Management Information Disclosure Vulnerability

  • CVE-2020-8585MedJan 28, 2021
    risk 0.36cvss 5.5epss 0.00

    OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthorized users via the use of PuTTY Link (plink).

  • CVE-2020-28935MedDec 7, 2020
    risk 0.36cvss 5.5epss 0.00

    NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local vulnerability that would allow for a local symlink attack. When writing the PID file, Unbound and NSD create the file if it is not there, or open an…

  • CVE-2020-6015MedNov 5, 2020
    risk 0.36cvss 5.5epss 0.00

    Check Point Endpoint Security for Windows before E84.10 can reach denial of service during clean install of the client which will prevent the storage of service log files in non-standard locations.

  • CVE-2018-21269MedOct 27, 2020
    risk 0.36cvss 5.5epss 0.00

    checkpath in OpenRC through 0.42.1 might allow local users to take ownership of arbitrary files because a non-terminal path component can be a symlink.

  • CVE-2017-18925MedOct 26, 2020
    risk 0.36cvss 5.5epss 0.00

    opentmpfiles through 0.3.1 allows local users to take ownership of arbitrary files because d entries are mishandled and allow a symlink attack.

  • CVE-2020-25289MedSep 13, 2020
    risk 0.36cvss 5.5epss 0.00

    The VPN service in AVAST SecureLine before 5.6.4982.470 allows local users to write to arbitrary files via an Object Manager symbolic link from the log directory (which has weak permissions).

  • CVE-2020-7325MedSep 9, 2020
    risk 0.36cvss 5.5epss 0.00

    Privilege Escalation vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to access files which the user otherwise would not have access to via manipulating symbolic links to redirect McAfee file operations to an unintended file.

  • CVE-2020-24332MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt existing files, which could possibly lead to a DoS attack.

  • CVE-2020-0779MedMar 12, 2020
    risk 0.36cvss 5.5epss 0.01

    An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0798, CVE-2020-0814, CVE-2020-0842, CVE-2020-0843.

  • CVE-2012-6114MedJan 28, 2020
    risk 0.36cvss 5.5epss 0.00

    The git-changelog utility in git-extras 1.7.0 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/changelog or (2) /tmp/.git-effort.

  • CVE-2020-0616MedJan 14, 2020
    risk 0.36cvss 5.5epss 0.02

    A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'.

  • CVE-2019-8789MedDec 18, 2019
    risk 0.36cvss 5.5epss 0.01

    A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Parsing a maliciously crafted iBooks file may lead to disclosure of user information.

  • CVE-2019-8568MedDec 18, 2019
    risk 0.36cvss 5.5epss 0.00

    A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A local user may be able to modify protected parts of the file system.