VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,658)

page 7 of 83
  • CVE-2025-20003HigMay 13, 2025
    risk 0.53cvss 8.2epss 0.00

    Improper link resolution before file access ('Link Following') for some Intel(R) Graphics Driver software installers may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-28868HigDec 9, 2023
    risk 0.53cvss 8.1epss 0.01

    Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to delete arbitrary files on the operating system by creating a symbolic link.

  • CVE-2023-29351HigJun 14, 2023
    risk 0.53cvss 8.1epss 0.02

    Windows Group Policy Elevation of Privilege Vulnerability

  • CVE-2022-42291HigFeb 7, 2023
    risk 0.53cvss 8.2epss 0.00

    NVIDIA GeForce Experience contains a vulnerability in the installer, where a user installing the NVIDIA GeForce Experience software may inadvertently delete data from a linked location, which may lead to data tampering. An attacker does not have explicit control over the…

  • CVE-2022-36943HigJan 3, 2023
    risk 0.53cvss 8.1epss 0.01

    SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on the filesystem when opening a malicious ZIP containing a symlink as the first item.

  • CVE-2022-31258HigMay 20, 2022
    risk 0.53cvss 8.2epss 0.00

    In Checkmk before 1.6.0p29, 2.x before 2.0.0p25, and 2.1.x before 2.1.0b10, a site user can escalate to root by editing an OMD hook symlink.

  • CVE-2021-39135HigAug 31, 2021
    risk 0.53cvss 8.2epss 0.01

    `@npmcli/arborist`, the library that calculates dependency trees and manages the node_modules folder hierarchy for the npm command line interface, aims to guarantee that package dependency contracts will be met, and the extraction of package contents will always be performed…

  • CVE-2021-39134HigAug 31, 2021
    risk 0.53cvss 8.2epss 0.01

    `@npmcli/arborist`, the library that calculates dependency trees and manages the `node_modules` folder hierarchy for the npm command line interface, aims to guarantee that package dependency contracts will be met, and the extraction of package contents will always be performed…

  • CVE-2021-23892HigMay 12, 2021
    risk 0.53cvss 8.2epss 0.00

    By exploiting a time of check to time of use (TOCTOU) race condition during the Endpoint Security for Linux Threat Prevention and Firewall (ENSL TP/FW) installation process, a local user can perform a privilege escalation attack to obtain administrator privileges for the purpose…

  • CVE-2021-30356HigApr 22, 2021
    risk 0.53cvss 8.1epss 0.01

    A denial of service vulnerability was reported in Check Point Identity Agent before R81.018.0000, which could allow low privileged users to overwrite protected system files.

  • CVE-2021-21479CriFeb 9, 2021
    risk 0.53cvss 9.1epss 0.10

    In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.

  • CVE-2021-21125HigFeb 9, 2021
    risk 0.53cvss 8.1epss 0.08

    Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

  • CVE-2020-25744HigSep 18, 2020
    risk 0.53cvss 8.1epss 0.01

    SaferVPN before 5.0.3.3 on Windows could allow low-privileged users to create or overwrite arbitrary files, which could cause a denial of service (DoS) condition, because a symlink from %LOCALAPPDATA%\SaferVPN\Log is followed.

  • CVE-2020-11443HigMay 4, 2020
    risk 0.53cvss 8.1epss 0.02

    The Zoom IT installer for Windows (ZoomInstallerFull.msi) prior to version 4.6.10 deletes files located in %APPDATA%\Zoom before installing an updated version of the client. Standard users are able to write to this directory, and can write links to other directories on the…

  • CVE-2020-7250HigApr 15, 2020
    risk 0.53cvss 8.2epss 0.00

    Symbolic link manipulation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows authenticated local user to potentially gain an escalation of privileges by pointing the link to files which the user which not normally have…

  • CVE-2020-7040HigJan 21, 2020
    risk 0.53cvss 8.1epss 0.03

    storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. (Local users can also create a plain file named /tmp/storeBackup.lock to block use of storeBackup until an admin…

  • CVE-2011-1408HigOct 29, 2019
    risk 0.53cvss 8.2epss 0.02

    ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks.

  • CVE-2019-3567HigJun 3, 2019
    risk 0.53cvss 8.1epss 0.02

    In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard link a parent folder of a malicious binary to a folder with known 'safe' permissions. Under those circumstances osquery will load said malicious executable with…

  • CVE-2017-2619HigMar 12, 2018
    risk 0.53cvss 7.5epss 0.11

    Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access to areas of the server file system not exported under the share definition.

  • CVE-2026-53486CriJul 14, 2026
    risk 0.52cvss 9.1epss 0.01

    The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write files outside that directory because…