CWE-59: CWE-59

284
Total CVEs
13
Critical
203
High
7.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
30
2025
90
2024
70
2023
40
2022
20

Top Affected Vendors

1 Microsoft 75
2 Apple 24
3 Trendmicro 13
4 Dell 6
5 Canonical 6
6 Google 4
7 Avast 4
8 Malwarebytes 4
9 Tanium 3
10 Fedoraproject 3

All CWE-59 CVEs (284)

CVE-2025-34194
7.8

This vulnerability allows local unprivileged users to escalate privileges to SYSTEM level by exploiting insecure temporary file handling in Vasion Pri...

Sep 19, 2025
CVE-2025-55245
7.8

This CVE describes a local privilege escalation vulnerability in Xbox systems where an authorized attacker can exploit improper link resolution to gai...

Sep 9, 2025
CVE-2025-55317
7.8

This vulnerability in Microsoft AutoUpdate allows an authorized attacker to exploit improper link resolution to elevate privileges locally. Attackers ...

Sep 9, 2025
CVE-2025-49738
7.8

This vulnerability allows an authorized attacker with local access to exploit improper link resolution in Microsoft PC Manager, enabling privilege esc...

Jul 8, 2025
CVE-2025-48799
7.8

This CVE describes a local privilege escalation vulnerability in Windows Update Service where improper link resolution allows an authorized attacker t...

Jul 8, 2025
CVE-2025-30640
7.8

A link following vulnerability in Trend Micro Deep Security 20.0 agents allows local attackers to escalate privileges on affected systems. Attackers m...

Jun 17, 2025
CVE-2024-11857
7.8

This CVE describes a Link Following vulnerability in Realtek Bluetooth HCI Adaptor that allows local attackers with regular privileges to create symbo...

Jun 2, 2025
CVE-2025-29975
7.8

This vulnerability allows an authorized attacker to exploit improper link resolution in Microsoft PC Manager to elevate privileges locally. Attackers ...

May 13, 2025
CVE-2024-13944
7.8

This vulnerability allows local attackers on Windows systems running Norton Utilities Ultimate to escalate privileges to SYSTEM level by exploiting a ...

May 9, 2025
CVE-2024-13960
7.8

This CVE describes a local privilege escalation vulnerability in AVG TuneUp's service on Windows 10. Attackers with local access can exploit a TOCTTOU...

May 9, 2025
CVE-2024-13962
7.8

This CVE describes a local privilege escalation vulnerability in Avast Cleanup Premium's TuneupSvc service on Windows. Attackers with local access can...

May 9, 2025
CVE-2025-3224
7.8

A local privilege escalation vulnerability in Docker Desktop for Windows allows low-privileged users to gain SYSTEM privileges by exploiting the updat...

Apr 28, 2025
CVE-2025-21204
7.8

This vulnerability allows an authorized attacker with local access to exploit improper link resolution in the Windows Update Stack to elevate privileg...

Apr 8, 2025
CVE-2025-29795
7.8

This vulnerability in Microsoft Edge allows an authorized attacker to exploit improper link resolution to elevate privileges locally. It affects users...

Mar 23, 2025
CVE-2025-1683
7.8

This vulnerability in the 1E Client's Nomad module allows attackers with local unprivileged access on Windows systems to delete arbitrary files by exp...

Mar 12, 2025
CVE-2025-21420
EPSS 23.5% 7.8

This vulnerability allows an authenticated attacker to exploit the Windows Disk Cleanup Tool to gain SYSTEM-level privileges on affected systems. It a...

Feb 11, 2025
CVE-2025-21373
7.8

This Windows Installer vulnerability allows attackers to elevate privileges on affected systems by exploiting improper handling of file operations. It...

Feb 11, 2025
CVE-2025-21322
7.8

Microsoft PC Manager contains an elevation of privilege vulnerability (CWE-59) that allows authenticated attackers to gain SYSTEM-level privileges on ...

Feb 11, 2025
CVE-2025-0413
7.8

This vulnerability in Parallels Desktop's Technical Data Reporter component allows local attackers to escalate privileges by creating symbolic links t...

Feb 5, 2025
CVE-2024-52050
7.8

This vulnerability in Trend Micro Apex One's LogServer component allows a local attacker with low-privileged code execution to create arbitrary files,...

Dec 31, 2024
CVE-2024-13043
7.8

This vulnerability in Panda Security Dome allows local attackers to escalate privileges by exploiting a link following flaw in Hotspot Shield. Attacke...

Dec 30, 2024
CVE-2024-7241
7.8

This vulnerability allows local attackers to escalate privileges on Panda Security Dome installations by exploiting a link following flaw in the PSANH...

Nov 22, 2024
CVE-2024-7243
7.8

This vulnerability allows local attackers with initial low-privileged access to escalate privileges to SYSTEM level by exploiting a symbolic link/junc...

Nov 22, 2024
CVE-2024-7233
7.8

This vulnerability in Avast Free Antivirus allows local attackers to escalate privileges from a low-privileged user account to SYSTEM level by exploit...

Nov 22, 2024
CVE-2024-7237
7.8

This vulnerability in AVG AntiVirus Free allows local attackers to escalate privileges from a low-privileged user account to SYSTEM level by exploitin...

Nov 22, 2024
CVE-2024-7239
7.8

This vulnerability allows local attackers with low-privileged access to escalate privileges to SYSTEM level by exploiting a symbolic link handling fla...

Nov 22, 2024
CVE-2024-7227
7.8

This vulnerability in Avast Free Antivirus allows local attackers to escalate privileges to SYSTEM level by exploiting a symbolic link issue in the Av...

Nov 22, 2024
CVE-2024-7229
7.8

This vulnerability allows local attackers to escalate privileges on systems running Avast Cleanup Premium. Attackers with initial low-privileged acces...

Nov 22, 2024
CVE-2024-7231
7.8

This vulnerability in Avast Cleanup Premium allows local attackers to escalate privileges by exploiting a symbolic link issue in the Avast Cleanup Ser...

Nov 22, 2024
CVE-2024-6260
7.8

This vulnerability allows local attackers with low-privileged code execution to escalate privileges to SYSTEM level by exploiting a symbolic link hand...

Nov 22, 2024
CVE-2024-1868
7.8

This vulnerability in G DATA Total Security allows local attackers to escalate privileges from a low-privileged account to SYSTEM level by exploiting ...

Nov 22, 2024
CVE-2024-49051
7.8

This vulnerability in Microsoft PC Manager allows attackers to gain elevated privileges on affected systems. Attackers could execute arbitrary code wi...

Nov 12, 2024
CVE-2024-45316
7.8

This vulnerability in SonicWall Connect Tunnel allows standard users to delete arbitrary files and folders through improper link resolution, potential...

Oct 11, 2024
CVE-2024-43551
7.8

This Windows Storage Elevation of Privilege vulnerability allows authenticated attackers to gain SYSTEM-level privileges on affected systems. It affec...

Oct 8, 2024
CVE-2024-43501
7.8

This vulnerability in the Windows Common Log File System (CLFS) driver allows attackers to gain SYSTEM privileges by exploiting improper link resoluti...

Oct 8, 2024
CVE-2024-5928
7.8

This vulnerability in VIPRE Advanced Security's Patch Management Agent allows local attackers to escalate privileges by exploiting symbolic link handl...

Aug 21, 2024
CVE-2024-38098
7.8

This vulnerability allows an authenticated attacker with local access to elevate privileges on Azure Arc-enabled servers. Attackers could gain SYSTEM-...

Aug 13, 2024
CVE-2024-7250
7.8

This vulnerability in Comodo Internet Security Pro allows local attackers to escalate privileges from low-privileged user accounts to SYSTEM level by ...

Jul 29, 2024
CVE-2024-7252
7.8

This vulnerability in Comodo Internet Security Pro allows local attackers to escalate privileges from low-privileged user accounts to SYSTEM level by ...

Jul 29, 2024
CVE-2024-35261
7.8

This vulnerability in Azure Network Watcher VM Extension allows authenticated attackers to elevate privileges on affected virtual machines. Attackers ...

Jul 9, 2024
CVE-2024-6147
7.8

This vulnerability allows local attackers to escalate privileges on systems running Poly Plantronics Hub by exploiting a symbolic link flaw in the Spo...

Jun 20, 2024
CVE-2024-30104
7.8

This vulnerability allows attackers to execute arbitrary code on a victim's system by tricking them into opening a specially crafted Office document. ...

Jun 11, 2024
CVE-2024-4454
7.8

This vulnerability in WithSecure Elements Endpoint Protection allows local attackers to escalate privileges to SYSTEM level by exploiting a symbolic l...

May 22, 2024
CVE-2023-51636
7.8

This vulnerability in Avira Prime allows local attackers to escalate privileges from a low-privileged account to SYSTEM level by exploiting a symbolic...

May 22, 2024
CVE-2024-30060
7.8

CVE-2024-30060 is an elevation of privilege vulnerability in Azure Monitor Agent that allows authenticated attackers to gain SYSTEM-level privileges o...

May 16, 2024
CVE-2024-26238
7.8

This vulnerability allows attackers to elevate privileges on Windows systems by exploiting the PLUGScheduler scheduled task component. Attackers with ...

May 14, 2024
CVE-2023-50226
7.8

This vulnerability allows local attackers with low-privileged access to escalate to root privileges by exploiting a symbolic link issue in Parallels D...

May 3, 2024
CVE-2023-42099
7.8

This vulnerability allows local attackers to escalate privileges on systems running Intel Driver & Support Assistant (DSA) by exploiting a symbolic li...

May 3, 2024
CVE-2023-27347
7.8

This vulnerability in G DATA Total Security allows local attackers to escalate privileges from low-privileged user accounts to SYSTEM level by exploit...

May 3, 2024
CVE-2024-21447
7.8

CVE-2024-21447 is an elevation of privilege vulnerability in Windows Authentication that allows authenticated attackers to gain SYSTEM-level privilege...

Apr 9, 2024

About CWE-59 (CWE-59)

Our database tracks 284 CVEs classified as CWE-59, with 13 rated critical and 203 rated high severity. The average CVSS score for CWE-59 vulnerabilities is 7.4.

External reference: View CWE-59 on MITRE CWE →

Monitor CWE-59 Vulnerabilities

Get alerted when new CWE-59 CVEs affect your infrastructure.

Start Monitoring Free