Local privilege escalation during installation due to improper soft link handling. The following products are affected:
Wacom Drivers for Windows Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attac
Visual Studio Elevation of Privilege Vulnerability
Windows Runtime C++ Template Library Elevation of Privilege Vulnerability
Windows Container Manager Service Elevation of Privilege Vulnerability
Azure Network Watcher VM Agent Elevation of Privilege Vulnerability
Windows Authentication Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
Link following in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation o
Windows Kernel Elevation of Privilege Vulnerability
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
A symbolic link following vulnerability in Buildkite Elastic CI for AWS versions prior to 6.7.1 and 5.22.5 allows the bu
A vulnerability has been discovered in cloudflared's installer (<= 2023.3.0) for Windows 32-bits devices that allows a l
There is an arbitrary file reading vulnerability in Generex UPS CS141 below 2.06 version. An attacker, making use of the
UnRAR before 6.2.3 allows extraction of files outside of the destination folder via symlink chains.
An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows attackers to gain sensitive information
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12
Due to incorrect access control, unauthenticated remote attackers can view the /video.mjpg video stream of certain ABUS
Wacom Driver 6.3.46-1 for Windows and lower was discovered to contain an arbitrary file deletion vulnerability.
Azure Connected Machine Agent Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 AP
Docker Desktop for Windows before 4.6.0 allows attackers to overwrite any file through a symlink attack on the hyperv/cr
Windows Installer Elevation of Privilege Vulnerability
Malwarebytes Anti-Exploit 4.4.0.220 is vulnerable to arbitrary file deletion and denial of service via an ALPC message i
Microsoft Install Service Elevation of Privilege Vulnerability
Reliability Analysis Metrics Calculation (RacTask) Elevation of Privilege Vulnerability
In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink at
Windows Authentication Denial of Service Vulnerability
Windows Storage Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
An unprivileged (non-admin) user can exploit an Improper Access Control vulnerability in the Cloudflare WARP Client for
Due to a hardlink created in the ProgramData folder during the repair process of the software, the installer (MSI) of WA
Windows Installer Elevation of Privilege Vulnerability
Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
Windows Search Service Elevation of Privilege Vulnerability
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that allows users with access to th
An Improper Link Resolution Before File Access vulnerability in console port access of Juniper Networks Junos OS on NFX
Dell PowerScale OneFS version 9.5.0.0 contains improper link resolution before file access vulnerability in isi_gather_
An NTFS Junction condition exists in the Qualys Cloud Agent for Windows platform in versions before 4.8.0.31. Attackers
Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an Insecure Operation on Wind
A symlink following vulnerability was found in Samba, where a user can create a symbolic link that will make 'smbd' esca
imapsync through 2.229 uses predictable paths under /tmp and /var/tmp in its default mode of operation. Both of these ar
Uploading files which contain symlinks may have allowed an attacker to trick a user into submitting sensitive data to a
The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that d
A website could have obscured the full screen notification by using a URL with a scheme handled by an external program,
Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the directory from which a
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers read the contents of arbitrary files on
Windows Malicious Software Removal Tool Elevation of Privilege Vulnerability
Frequently Asked Questions
What is CWE-59?
CWE-59 (CWE-59) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-59?
There are 1,879 CVE records associated with CWE-59 in our database. Of these, 45 are critical severity, 691 are high severity, and 425 are medium severity.
How can I protect against CWE-59 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-59 using AI-powered security agents.
Detect CWE-59 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-59 vulnerabilities across your infrastructure.
Get Started