A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file pa
A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker t
Microsoft Azure File Sync Elevation of Privilege Vulnerability
An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Windows a
In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap
NETGEAR RAX30 USB Share Link Following Information Disclosure Vulnerability. This vulnerability allows physically presen
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 a
Microsoft Azure File Sync Elevation of Privilege Vulnerability
A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a
Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to ove
Dell AppSync, version 4.6.0.x, contain a Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure h
Improper Link Resolution Before File Access in GitHub repository froxlor/froxlor prior to 2.1.0.
Wings is Pterodactyl's server control plane. This vulnerability can be used to delete files and directories recursively
An arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1 allows
Minecraft through 1.19 and 1.20 pre-releases before 7 (Java) allow arbitrary file overwrite, and possibly code execution
Arbitrary File Overwrite in Eclipse JGit <= 6.6.0 In Eclipse JGit, all versions <= 6.6.0.202305301015-r, a symbolic lin
Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privile
Wings is Pterodactyl's server control plane. Affected versions are subject to a vulnerability which can be used to creat
1E Client installer can perform arbitrary file deletion on protected files. A non-privileged user could provide a sym
NVIDIA GeForce Experience contains a vulnerability in the installer, where a user installing the NVIDIA GeForce Experie
SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths
Windows Group Policy Elevation of Privilege Vulnerability
Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the expected directory dur
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to delete arbitrary files on the operati
Windows Print Spooler Elevation of Privilege Vulnerability
uptimed before 0.4.6-r1 on Gentoo allows local users (with access to the uptimed user account) to gain root privileges b
Arbitrary File Delete vulnerability in Razer Central before v7.8.0.381 when handling files in the Accounts directory.
A link following vulnerability in the scanning function of Trend Micro Apex One agent could allow a local attacker to es
A security agent link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to quaranti
A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to exploit the vulner
Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability
In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the loc
Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:\AdwCleaner\Logs
SysInternals Sysmon for Windows Elevation of Privilege Vulnerability
Wacom Tablet Driver installer prior to 6.4.2-1 (for macOS) contains an improper link resolution before file access vulne
Insufficient data validation in Installer in Google Chrome on Windows prior to 114.0.5735.90 allowed a local attacker to
RenderDoc before 1.27 allows local privilege escalation via a symlink attack. It relies on the /tmp/RenderDoc directory
Windows Container Manager Service Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
Microsoft Office Elevation of Privilege Vulnerability
Connected User Experiences and Telemetry Elevation of Privilege Vulnerability
Windows Image Acquisition Elevation of Privilege Vulnerability
Connected User Experiences and Telemetry Elevation of Privilege Vulnerability
Windows Error Reporting Service Elevation of Privilege Vulnerability
Reliability Analysis Metrics Calculation Engine (RACEng) Elevation of Privilege Vulnerability
Windows System Assessment Tool Elevation of Privilege Vulnerability
Microsoft Windows Defender Elevation of Privilege Vulnerability
Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perfo
Frequently Asked Questions
What is CWE-59?
CWE-59 (CWE-59) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-59?
There are 1,879 CVE records associated with CWE-59 in our database. Of these, 45 are critical severity, 691 are high severity, and 425 are medium severity.
How can I protect against CWE-59 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-59 using AI-powered security agents.
Detect CWE-59 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-59 vulnerabilities across your infrastructure.
Get Started