Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-59

45
CRITICAL
691
HIGH
425
MEDIUM
43
LOW
1,232 CVEs · Page 14/25
7.8
CVE-2022-46869

Local privilege escalation during installation due to improper soft link handling. The following products are affected:

7.8
CVE-2023-32163

Wacom Drivers for Windows Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attac

7.8
CVE-2023-36758

Visual Studio Elevation of Privilege Vulnerability

7.8
CVE-2023-36711

Windows Runtime C++ Template Library Elevation of Privilege Vulnerability

7.8
CVE-2023-36723

Windows Container Manager Service Elevation of Privilege Vulnerability

7.8
CVE-2023-36737

Azure Network Watcher VM Agent Elevation of Privilege Vulnerability

7.8
CVE-2023-36047

Windows Authentication Elevation of Privilege Vulnerability

7.8
CVE-2023-36705

Windows Installer Elevation of Privilege Vulnerability

7.8
CVE-2023-43590

Link following in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation o

7.8
CVE-2023-35633

Windows Kernel Elevation of Privilege Vulnerability

7.8
CVE-2023-36391

Local Security Authority Subsystem Service Elevation of Privilege Vulnerability

7.8
CVE-2023-43116

A symbolic link following vulnerability in Buildkite Elastic CI for AWS versions prior to 6.7.1 and 5.22.5 allows the bu

7.5
CVE-2023-1314

A vulnerability has been discovered in cloudflared's installer (<= 2023.3.0) for Windows 32-bits devices that allows a l

7.5
CVE-2022-47188

There is an arbitrary file reading vulnerability in Generex UPS CS141 below 2.06 version. An attacker, making use of the

7.5
CVE-2022-48579

UnRAR before 6.2.3 allows extraction of files outside of the destination folder via symlink chains.

7.5
CVE-2023-34723

An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows attackers to gain sensitive information

7.5
CVE-2023-42844

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12

7.5
CVE-2018-17559

Due to incorrect access control, unauthenticated remote attackers can view the /video.mjpg video stream of certain ABUS

7.3
CVE-2022-38604

Wacom Driver 6.3.46-1 for Windows and lower was discovered to contain an arbitrary file deletion vulnerability.

7.3
CVE-2023-35624

Azure Connected Machine Agent Elevation of Privilege Vulnerability

7.1
CVE-2023-21760

Windows Print Spooler Elevation of Privilege Vulnerability

7.1
CVE-2023-28222

Windows Kernel Elevation of Privilege Vulnerability

7.1
CVE-2022-31647

Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 AP

7.1
CVE-2022-34292

Docker Desktop for Windows before 4.6.0 allows attackers to overwrite any file through a symlink attack on the hyperv/cr

7.1
CVE-2023-24904

Windows Installer Elevation of Privilege Vulnerability

7.1
CVE-2023-27469

Malwarebytes Anti-Exploit 4.4.0.220 is vulnerable to arbitrary file deletion and denial of service via an ALPC message i

7.1
CVE-2023-35347

Microsoft Install Service Elevation of Privilege Vulnerability

7.1
CVE-2023-36876

Reliability Analysis Metrics Calculation (RacTask) Elevation of Privilege Vulnerability

7.1
CVE-2020-28407

In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink at

7.1
CVE-2023-36046

Windows Authentication Denial of Service Vulnerability

7.1
CVE-2023-36399

Windows Storage Elevation of Privilege Vulnerability

7.0
CVE-2023-21542

Windows Installer Elevation of Privilege Vulnerability

7.0
CVE-2023-1412

An unprivileged (non-admin) user can exploit an Improper Access Control vulnerability in the Cloudflare WARP Client for

7.0
CVE-2023-0652

Due to a hardlink created in the ProgramData folder during the repair process of the software, the installer (MSI) of WA

7.0
CVE-2023-32050

Windows Installer Elevation of Privilege Vulnerability

7.0
CVE-2023-36568

Microsoft Office Click-To-Run Elevation of Privilege Vulnerability

7.0
CVE-2023-36394

Windows Search Service Elevation of Privilege Vulnerability

6.8
CVE-2023-27850

NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that allows users with access to th

6.8
CVE-2023-28972

An Improper Link Resolution Before File Access vulnerability in console port access of Juniper Networks Junos OS on NFX

6.7
CVE-2023-25940

Dell PowerScale OneFS version 9.5.0.0 contains improper link resolution before file access vulnerability in isi_gather_

6.7
CVE-2023-28141

An NTFS Junction condition exists in the Qualys Cloud Agent for Windows platform in versions before 4.8.0.31. Attackers

6.7
CVE-2023-28065

Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an Insecure Operation on Wind

6.5
CVE-2022-3592

A symlink following vulnerability was found in Samba, where a user can create a symbolic link that will make 'smbd' esca

6.5
CVE-2023-34204

imapsync through 2.229 uses predictable paths under /tmp and /var/tmp in its default mode of operation. Both of these ar

6.5
CVE-2023-37206

Uploading files which contain symlinks may have allowed an attacker to trick a user into submitting sensitive data to a

6.5
CVE-2023-4052

The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that d

6.5
CVE-2023-4053

A website could have obscured the full screen notification by using a URL with a scheme handled by an external program,

6.5
CVE-2023-46655

Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the directory from which a

6.5
CVE-2023-28869

Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers read the contents of arbitrary files on

6.3
CVE-2023-21725

Windows Malicious Software Removal Tool Elevation of Privilege Vulnerability

Frequently Asked Questions

What is CWE-59?

CWE-59 (CWE-59) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-59?

There are 1,879 CVE records associated with CWE-59 in our database. Of these, 45 are critical severity, 691 are high severity, and 425 are medium severity.

How can I protect against CWE-59 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-59 using AI-powered security agents.

Detect CWE-59 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-59 vulnerabilities across your infrastructure.

Get Started