VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,754)

page 48 of 88
  • CVE-2024-12754MedDec 30, 2024
    risk 0.36cvss 5.5epss 0.01

    AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order…

  • CVE-2024-44211MedDec 20, 2024
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be able to access user-sensitive data.

  • CVE-2024-7236MedNov 22, 2024
    risk 0.36cvss 5.5epss 0.00

    AVG AntiVirus Free icarus Arbitrary File Creation Denial of Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AVG AntiVirus Free. An attacker must first obtain the ability to execute…

  • CVE-2024-7235MedNov 22, 2024
    risk 0.36cvss 5.5epss 0.00

    AVG AntiVirus Free Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AVG AntiVirus Free. An attacker must first obtain the ability to execute low-privileged code on the…

  • CVE-2024-7228MedNov 22, 2024
    risk 0.36cvss 5.5epss 0.00

    Avast Free Antivirus Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Avast Free Antivirus. An attacker must first obtain the ability to execute low-privileged code on…

  • CVE-2024-44273MedOct 28, 2024
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. A malicious app may be able to access private information.

  • CVE-2024-44264MedOct 28, 2024
    risk 0.36cvss 5.5epss 0.01

    This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious app may be able to create symlinks to protected regions of the disk.

  • CVE-2024-44175MedOct 28, 2024
    risk 0.36cvss 5.5epss 0.01

    This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7.1. An app may be able to access sensitive user data.

  • CVE-2024-45315MedOct 11, 2024
    risk 0.36cvss 5.5epss 0.00

    The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard privileges to create arbitrary folders and files, potentially leading to local Denial of…

  • CVE-2024-43603MedOct 8, 2024
    risk 0.36cvss 5.5epss 0.01

    Visual Studio Collector Service Denial of Service Vulnerability

  • CVE-2024-44178MedSep 17, 2024
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An app may be able to modify protected parts of the file system.

  • CVE-2024-44131MedSep 17, 2024
    risk 0.36cvss 5.5epss 0.01

    This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to access sensitive user data.

  • CVE-2024-30065MedJun 11, 2024
    risk 0.36cvss 5.5epss 0.01

    Windows Themes Denial of Service Vulnerability

  • CVE-2024-23285MedMar 8, 2024
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma 14.4. An app may be able to create symlinks to protected regions of the disk.

  • CVE-2024-0068MedFeb 29, 2024
    risk 0.36cvss 5.5epss 0.00

    Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows File Manipulation.This issue affects Workforce Access: before 8.7.1.

  • CVE-2023-51654MedDec 26, 2023
    risk 0.36cvss 5.5epss 0.00

    Improper link resolution before file access ('Link Following') issue exists in iPrint&Scan Desktop for Windows versions 11.0.0 and earlier. A symlink attack by a malicious user may cause a Denial-of-service (DoS) condition on the PC.

  • CVE-2023-41968MedSep 27, 2023
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to read arbitrary files.

  • CVE-2023-32556MedJun 26, 2023
    risk 0.36cvss 5.5epss 0.00

    A link following vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to disclose sensitive information. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to…

  • CVE-2023-24577MedMar 13, 2023
    risk 0.36cvss 5.5epss 0.00

    McAfee Total Protection prior to 16.0.50 allows attackers to elevate user privileges due to Improper Link Resolution via registry keys. This could enable a user with lower privileges to execute unauthorized tasks.

  • CVE-2023-21567MedFeb 14, 2023
    risk 0.36cvss 5.6epss 0.01

    Visual Studio Denial of Service Vulnerability