Vulnerabilities > Improper Link Resolution Before File Access ('Link Following')

DATE CVE VULNERABILITY TITLE RISK
2024-07-09 CVE-2024-38022 Link Following vulnerability in Microsoft products
Windows Image Acquisition Elevation of Privilege Vulnerability
local
high complexity
microsoft CWE-59
7.0
2024-06-11 CVE-2024-30104 Link Following vulnerability in Microsoft 365 Apps and Office
Microsoft Office Remote Code Execution Vulnerability
local
low complexity
microsoft CWE-59
7.8
2024-06-11 CVE-2024-35253 Link Following vulnerability in Microsoft Azure File Sync
Microsoft Azure File Sync Elevation of Privilege Vulnerability
local
high complexity
microsoft CWE-59
4.4
2024-06-11 CVE-2024-35254 Link Following vulnerability in Microsoft Azure Monitor Agent
Azure Monitor Agent Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-59
7.1
2024-06-11 CVE-2024-30093 Link Following vulnerability in Microsoft products
Windows Storage Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-59
7.3
2024-06-10 CVE-2024-27885 Link Following vulnerability in Apple Macos
This issue was addressed with improved validation of symlinks.
local
low complexity
apple CWE-59
6.3
2024-06-10 CVE-2024-5102 Link Following vulnerability in Avast Antivirus
A sym-linked file accessed via the repair function in Avast Antivirus <24.2 on Windows may allow user to elevate privilege to delete arbitrary files or run processes as NT AUTHORITY\SYSTEM. The vulnerability exists within the "Repair" (settings -> troubleshooting -> repair) feature, which attempts to delete a file in the current user's AppData directory as NT AUTHORITY\SYSTEM.
local
high complexity
avast CWE-59
7.0
2024-05-14 CVE-2024-32002 Link Following vulnerability in GIT
Git is a revision control system.
network
high complexity
git CWE-59
critical
9.0
2024-02-06 CVE-2023-32454 Link Following vulnerability in Dell Update Package Framework 3.8.3.67
DUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerability.
local
low complexity
dell CWE-59
7.1
2024-02-06 CVE-2023-32474 Link Following vulnerability in Dell Display Manager 2.0.0/2.1.0/2.1.1
Dell Display Manager application, version 2.1.1.17 and prior, contain an insecure operation on windows junction/mount point.
local
low complexity
dell CWE-59
6.6