VYPR

CWE-64

Windows Shortcut Following (.LNK)

VariantIncompleteLikelihood: Low

Description

The product, when opening a file or directory, does not sufficiently handle when the file is a Windows shortcut (.LNK) whose target is outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (13)

  • CVE-2025-53503HigJul 10, 2025
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Cleaner One Pro is vulnerable to a Privilege Escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own.

  • CVE-2025-52837HigJul 10, 2025
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could allow an attacker the opportunity to abuse symbolic links and other methods to delete any file/folder and achieve privilege…

  • CVE-2025-52521HigJul 10, 2025
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own.

  • CVE-2025-49385HigJun 17, 2025
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own.

  • CVE-2025-49384HigJun 17, 2025
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own.

  • CVE-2025-48443MedJun 17, 2025
    risk 0.44cvss 6.7epss 0.00

    Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Local Privilege Escalation Vulnerability that could allow a local attacker to leverage this vulnerability to delete files in the context of an administrator when the…

  • CVE-2021-1492MedMar 25, 2021
    risk 0.43cvss 6.6epss 0.00

    The Duo Authentication Proxy installer prior to 5.2.1 did not properly validate file installation paths. This allows an attacker with local user privileges to coerce the installer to write to arbitrary privileged directories. If successful, an attacker can manipulate files used…

  • CVE-2021-41562MedNov 3, 2021
    risk 0.40cvss 6.1epss 0.00

    A vulnerability in Snow Snow Agent for Windows allows a non-admin user to cause arbitrary deletion of files. This issue affects: Snow Snow Agent for Windows version 5.0.0 to 6.7.1 on Windows.

  • CVE-2021-39391MedSep 14, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability exists in the admin panel in Beego v2.0.1 via the URI path in an HTTP request, which is activated by administrators viewing the "Request Statistics" page.

  • CVE-2018-16481MedFeb 1, 2019
    risk 0.40cvss 6.1epss 0.01

    A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's browser due to the absence of sanitization of the paths before rendering.

  • CVE-2025-7376MedAug 6, 2025
    risk 0.38cvss 5.9epss 0.00

    Windows Shortcut Following (.LNK) vulnerability in multiple processes of Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric MobileHMI versions 10.97.3 and prior, Mitsubishi Electric Hyper…

  • CVE-2012-6708MedJan 18, 2018
    risk 0.36cvss 6.1epss 0.09

    jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions, jQuery determined whether the input was HTML by looking for the '<' character anywhere…

  • CVE-2024-21910MedJan 3, 2024
    risk 0.33cvss 6.1epss 0.01

    TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would result in the execution of arbitrary JavaScript in an editing user's browser.