ESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard l
Symantec Endpoint Protection, prior to 14.3, may not respect file permissions when writing to log files that are replace
Inappropriate implementation in installer in Google Chrome on OS X prior to 83.0.4103.61 allowed a local attacker to per
A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple cont
An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd servi
NCP Secure Enterprise Client before 10.15 r47589 allows a symbolic link attack on enumusb.reg via Support Assistant.
ABBYY network license server in ABBYY FineReader 15 before Release 4 (aka 15.0.112.2130) allows escalation of privileges
Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following.
checkinstall 1.6.2, when used to create a package that contains a symlink, may trigger the creation of a mode 0777 execu
A vulnerability in Trend Micro Apex One, OfficeScan XG SP1, Worry-Free Business Security 10 SP1 and Worry-Free Business
A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services
SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivilege
Inappropriate implementation in installer in Google Chrome prior to 84.0.4147.125 allowed a local attacker to potentiall
Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an aut
A vulnerability in Trend Micro OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any
Trend Micro Antivirus for Mac 2020 (Consumer) is vulnerable to a symbolic link privilege escalation attack where an atta
<p>An elevation of privilege vulnerability exists when Group Policy improperly checks access. An attacker who successful
An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization
An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization
Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local attacker to potentiall
Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on Program
Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placin
Privilege escalation via arbitrary file write in pritunl electron client 1.0.1116.6 through v1.2.2550.20. Successful exp
An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization
The test suite in libopendkim in OpenDKIM through 2.10.3 allows local users to gain privileges via a symlink attack agai
UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; ope
A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in SUSE Linux Enterprise Server 15; openSUSE
The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap 15.1 allows local attackers to escalate
A symlink following vulnerability in the packaging of mailman in SUSE Linux Enterprise Server 11, SUSE Linux Enterprise
A Symbolic Link (Symlink) Following vulnerability in the packaging of munin in openSUSE Factory, Leap 15.1 allows local
UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of gnump3d in openSUSE Leap 15.1 allows local atta
UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of privoxy on openSUSE Leap 15.1, Factory allows l
Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to delete files t
HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protec
ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sop
A vulnerability in the improper handling of symbolic links in Bitdefender Antivirus Free can allow an unprivileged user
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlin
Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is li
A denial of service vulnerability exists when the Visual Studio Extension Installer Service improperly handles hard link
A vulnerability in the improper handling of junctions in Bitdefender Antivirus Free can allow an unprivileged user to su
IOBit Advanced SystemCare Free 13.5.0.263 allows local users to gain privileges for file deletion by manipulating the Cl
<p>An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles s
<p>An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles s
In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the loca
log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By default, it uses a
init_tmp in TeeJee.FileSystem.vala in Timeshift before 20.03 unsafely reuses a preexisting temporary directory in the pr
Docker Desktop allows local privilege escalation to NT AUTHORITY\SYSTEM because it mishandles the collection of diagnost
daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-up
Apport creates a world writable lock file with root ownership in the world writable /var/lock/apport directory. If the a
An improper link resolution vulnerability affects Kata Containers versions prior to 1.11.0. Upon container teardown, a m
Frequently Asked Questions
What is CWE-59?
CWE-59 (CWE-59) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-59?
There are 1,879 CVE records associated with CWE-59 in our database. Of these, 45 are critical severity, 691 are high severity, and 425 are medium severity.
How can I protect against CWE-59 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-59 using AI-powered security agents.
Detect CWE-59 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-59 vulnerabilities across your infrastructure.
Get Started