VYPR

CWE-59

Improper Link Resolution Before File Access ('Link Following')

BaseDraftLikelihood: Medium

Description

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-132 · CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (1,754)

page 9 of 88
  • CVE-2000-0342HigApr 28, 2000
    risk 0.52cvss 7.5epss 0.03

    Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refers to the attachment, aka "Stealth Attachment."

  • CVE-2026-69289HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper link resolution before file access ('link following') in Windows Setup Files Cleanup allows an authorized attacker to elevate privileges locally.

  • CVE-2026-19820HigSep 1, 2026
    risk 0.51cvss —epss 0.00

    A vulnerability in the Backblaze Client allows a local user to make the system not bootable by creating a link from Backblaze's folder to Windows OS system files during a backup. Successful exploitation requires an administrator-level system change that results in the absence of…

  • CVE-2026-81572HigAug 27, 2026
    risk 0.51cvss 7.8epss 0.00

    In CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10, cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or…

  • CVE-2026-17171HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite arbitrary files due to improper resolution of symbolic links.

  • CVE-2026-62832HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.03

    Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62812HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62807HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62803HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62776HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62761HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

  • CVE-2026-61358HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.04

    Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-12410HigAug 5, 2026
    risk 0.51cvss 7.8epss 0.00

    Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-privileged attacker to escalate privileges to SYSTEM via a symlink/junction created during application uninstallation, which CCleaner follows when deleting the…

  • CVE-2026-44274HigJun 22, 2026
    risk 0.51cvss 7.8epss 0.00

    Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Before File Access vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

  • CVE-2026-50511HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

  • CVE-2026-45586HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.04

    Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42989HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.02

    Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.

  • CVE-2025-71212HigMay 21, 2026
    risk 0.51cvss 7.8epss 0.01

    A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit…

  • CVE-2026-42834HigMay 20, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-44471HigMay 13, 2026
    risk 0.51cvss 7.8epss 0.00

    gitoxide is an implementation of git written in Rust. Prior to 0.21.1, a malicious tree can be constructed that will, when checked out with gitoxide, permit writing an attacker-controlled symlink into any existing directory the user has write access to. During checkout, all…