This vulnerability allows local attackers to delete arbitrary directories on affected installations of Avast Premium Sec
Improper Link Resolution Before File Access ('Link Following') vulnerability in the EPAG component of Bitdefender Endpoi
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthorize
autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Dir
Windows Mobile Device Management Information Disclosure Vulnerability
A vulnerability exists in IBM SPSS Modeler Subscription Installer that allows a user with create symbolic link permissio
autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Dire
A security vulnerability that can lead to local privilege escalation has been found in ’guix-daemon’. It affects multi-u
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. T
A validation issue related to hard link behavior was addressed with improved sandbox restrictions. This issue is fixed i
A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to overwrite arbitr
Windows Installer Elevation of Privilege Vulnerability
An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATIO
It was discovered that the process_report() function in data/whoopsie-upload-all allowed arbitrary file writes via symli
Windows 10 Update Assistant Elevation of Privilege Vulnerability
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow a local user to access and change the
IBM Security Identity Governance and Intelligence 5.2.6 does not set the secure attribute on authorization tokens or ses
fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory
A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up i
In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps director
bblfshd is an open source self-hosted server for source code parsing. In bblfshd before commit 4265465b9b6fb5663c30ee438
The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existen
There is an information leak vulnerability in the digital media player (DMS) of ZTE's residential gateway product. The a
The decompress package before 4.2.1 for Node.js is vulnerable to Arbitrary File Write via ../ in an archive member, when
Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful
Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful
An issue was discovered in G-Data before 25.5.9.25 using Symbolic links, it is possible to abuse the infected-file resto
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The system area allows arbi
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an
Mac Endpoint for Sophos Central before 9.9.6 and Mac Endpoint for Sophos Home before 2.2.6 allow Privilege Escalation.
Little Snitch version 4.5.1 and older changed ownership of a directory path controlled by the user. This allowed the use
Overwolf before 0.149.2.30 mishandles Symbolic Links during updates, causing elevation of privileges.
Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Updat
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of exim in openSUSE Factory allows local attacke
Symbolic link manipulation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Upd
storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks tha
The Zoom IT installer for Windows (ZoomInstallerFull.msi) prior to version 4.6.10 deletes files located in %APPDATA%\Zoo
SaferVPN before 5.0.3.3 on Windows could allow low-privileged users to create or overwrite arbitrary files, which could
The default event handling scripts in Automatic Bug Reporting Tool (ABRT) allow local users to gain privileges as demons
An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this
mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root becau
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'W
The AUEPLauncher service in Radeon AMD User Experience Program Launcher through 1.0.0.1 on Windows allows elevation of p
The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a pr
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
Writing to an unprivileged file from a privileged OVRRedir.exe process in Oculus Desktop before 1.44.0.32849 on Windows
The Sierra Wireless Windows Mobile Broadband Driver Packages (MBDP) before build 5043 allows an unprivileged user to ove
Avira Antivirus before 5.0.2003.1821 on Windows allows privilege escalation or a denial of service via abuse of a symlin
Frequently Asked Questions
What is CWE-59?
CWE-59 (CWE-59) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-59?
There are 1,879 CVE records associated with CWE-59 in our database. Of these, 45 are critical severity, 691 are high severity, and 425 are medium severity.
How can I protect against CWE-59 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-59 using AI-powered security agents.
Detect CWE-59 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-59 vulnerabilities across your infrastructure.
Get Started