A validation issue existed in the handling of symlinks and was addressed with improved validation of symlinks. This issu
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file
Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker
Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.684 allows a local, low privileged, attacker
Comodo Antivirus 12.2.2.8012 has a quarantine flaw that allows privilege escalation. To escalate privilege, a low-privil
A link following vulnerability in the scanning function of Trend Micro Apex One and Worry-Free Business Security agents
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the t
An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control
Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow
Trend Micro Security 2022 (consumer) has a link following vulnerability where an attacker with lower privileges could ma
A link following vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could
multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction w
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13. Processing a mal
Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protec
A vulnerability was found in Freedom of the Press SecureDrop. It has been rated as critical. Affected by this issue is s
A link following vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One a
ROG Live Service’s function for deleting temp files created by installation has an improper link resolution before file
A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail system
An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) o
The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the
Warpinator through 1.2.14 allows access outside of an intended directory, as demonstrated by symbolic directory links.
A link following vulnerability in Trend Micro Antivirus for Mac 11.5 could allow an attacker to create a specially-craft
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file
A link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service
A link following denial-of-service vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free B
A link following denial-of-service vulnerability in Trend Micro Worry-Free Business Security (on prem only) could allow
Windows Print Spooler Elevation of Privilege Vulnerability
Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable
SWHKD 1.1.5 unsafely uses the /tmp/swhks.pid pathname. There can be data loss or a denial of service.
Trend Micro Maximum Security 2022 is vulnerable to a link following vulnerability that could allow a low privileged loca
AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own
A UNIX Symbolic Link (Symlink) Following vulnerability in keylime of openSUSE Tumbleweed allows local attackers to escal
Windows User Profile Service Elevation of Privilege Vulnerability
An improper link resolution before file access ('link following') vulnerability exists in the Palo Alto Networks GlobalP
An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended access restrictions on mount
In connsyslogger, there is a possible symbolic link following due to improper link resolution. This could lead to local
In mobile_log_d, there is a possible symbolic link following due to an improper link resolution. This could lead to loca
In netdiag, there is a possible symbolic link following due to an improper link resolution. This could lead to local esc
Thales Safenet Authentication Client (SAC) for Linux and Windows through 10.7.7 creates insecure temporary hid and lock
In sound driver, there is a possible information disclosure due to symlink following. This could lead to local informati
A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing
It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the par
An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can gain privileges via a symlink attack on /tmp
Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier follows symbolic links to locations outside of the checko
Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier follows symbolic links to locations outsi
Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier follows symbolic links to locations outside of the ch
An improper link resolution before file access ('Link Following') vulnerability has been reported to affect QNAP device
Frequently Asked Questions
What is CWE-59?
CWE-59 (CWE-59) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-59?
There are 1,879 CVE records associated with CWE-59 in our database. Of these, 45 are critical severity, 691 are high severity, and 425 are medium severity.
How can I protect against CWE-59 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-59 using AI-powered security agents.
Detect CWE-59 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-59 vulnerabilities across your infrastructure.
Get Started