CWE-59: CWE-59
Yearly Trend
Top Affected Vendors
All CWE-59 CVEs (284)
This vulnerability allows local unprivileged users to escalate privileges to SYSTEM level by exploiting insecure temporary file handling in Vasion Pri...
Sep 19, 2025This CVE describes a local privilege escalation vulnerability in Xbox systems where an authorized attacker can exploit improper link resolution to gai...
Sep 9, 2025This vulnerability in Microsoft AutoUpdate allows an authorized attacker to exploit improper link resolution to elevate privileges locally. Attackers ...
Sep 9, 2025This vulnerability allows an authorized attacker with local access to exploit improper link resolution in Microsoft PC Manager, enabling privilege esc...
Jul 8, 2025This CVE describes a local privilege escalation vulnerability in Windows Update Service where improper link resolution allows an authorized attacker t...
Jul 8, 2025A link following vulnerability in Trend Micro Deep Security 20.0 agents allows local attackers to escalate privileges on affected systems. Attackers m...
Jun 17, 2025This CVE describes a Link Following vulnerability in Realtek Bluetooth HCI Adaptor that allows local attackers with regular privileges to create symbo...
Jun 2, 2025This vulnerability allows an authorized attacker to exploit improper link resolution in Microsoft PC Manager to elevate privileges locally. Attackers ...
May 13, 2025This vulnerability allows local attackers on Windows systems running Norton Utilities Ultimate to escalate privileges to SYSTEM level by exploiting a ...
May 9, 2025This CVE describes a local privilege escalation vulnerability in AVG TuneUp's service on Windows 10. Attackers with local access can exploit a TOCTTOU...
May 9, 2025This CVE describes a local privilege escalation vulnerability in Avast Cleanup Premium's TuneupSvc service on Windows. Attackers with local access can...
May 9, 2025A local privilege escalation vulnerability in Docker Desktop for Windows allows low-privileged users to gain SYSTEM privileges by exploiting the updat...
Apr 28, 2025This vulnerability allows an authorized attacker with local access to exploit improper link resolution in the Windows Update Stack to elevate privileg...
Apr 8, 2025This vulnerability in Microsoft Edge allows an authorized attacker to exploit improper link resolution to elevate privileges locally. It affects users...
Mar 23, 2025This vulnerability in the 1E Client's Nomad module allows attackers with local unprivileged access on Windows systems to delete arbitrary files by exp...
Mar 12, 2025This vulnerability allows an authenticated attacker to exploit the Windows Disk Cleanup Tool to gain SYSTEM-level privileges on affected systems. It a...
Feb 11, 2025This Windows Installer vulnerability allows attackers to elevate privileges on affected systems by exploiting improper handling of file operations. It...
Feb 11, 2025Microsoft PC Manager contains an elevation of privilege vulnerability (CWE-59) that allows authenticated attackers to gain SYSTEM-level privileges on ...
Feb 11, 2025This vulnerability in Parallels Desktop's Technical Data Reporter component allows local attackers to escalate privileges by creating symbolic links t...
Feb 5, 2025This vulnerability in Trend Micro Apex One's LogServer component allows a local attacker with low-privileged code execution to create arbitrary files,...
Dec 31, 2024This vulnerability in Panda Security Dome allows local attackers to escalate privileges by exploiting a link following flaw in Hotspot Shield. Attacke...
Dec 30, 2024This vulnerability allows local attackers to escalate privileges on Panda Security Dome installations by exploiting a link following flaw in the PSANH...
Nov 22, 2024This vulnerability allows local attackers with initial low-privileged access to escalate privileges to SYSTEM level by exploiting a symbolic link/junc...
Nov 22, 2024This vulnerability in Avast Free Antivirus allows local attackers to escalate privileges from a low-privileged user account to SYSTEM level by exploit...
Nov 22, 2024This vulnerability in AVG AntiVirus Free allows local attackers to escalate privileges from a low-privileged user account to SYSTEM level by exploitin...
Nov 22, 2024This vulnerability allows local attackers with low-privileged access to escalate privileges to SYSTEM level by exploiting a symbolic link handling fla...
Nov 22, 2024This vulnerability in Avast Free Antivirus allows local attackers to escalate privileges to SYSTEM level by exploiting a symbolic link issue in the Av...
Nov 22, 2024This vulnerability allows local attackers to escalate privileges on systems running Avast Cleanup Premium. Attackers with initial low-privileged acces...
Nov 22, 2024This vulnerability in Avast Cleanup Premium allows local attackers to escalate privileges by exploiting a symbolic link issue in the Avast Cleanup Ser...
Nov 22, 2024This vulnerability allows local attackers with low-privileged code execution to escalate privileges to SYSTEM level by exploiting a symbolic link hand...
Nov 22, 2024This vulnerability in G DATA Total Security allows local attackers to escalate privileges from a low-privileged account to SYSTEM level by exploiting ...
Nov 22, 2024This vulnerability in Microsoft PC Manager allows attackers to gain elevated privileges on affected systems. Attackers could execute arbitrary code wi...
Nov 12, 2024This vulnerability in SonicWall Connect Tunnel allows standard users to delete arbitrary files and folders through improper link resolution, potential...
Oct 11, 2024This Windows Storage Elevation of Privilege vulnerability allows authenticated attackers to gain SYSTEM-level privileges on affected systems. It affec...
Oct 8, 2024This vulnerability in the Windows Common Log File System (CLFS) driver allows attackers to gain SYSTEM privileges by exploiting improper link resoluti...
Oct 8, 2024This vulnerability in VIPRE Advanced Security's Patch Management Agent allows local attackers to escalate privileges by exploiting symbolic link handl...
Aug 21, 2024This vulnerability allows an authenticated attacker with local access to elevate privileges on Azure Arc-enabled servers. Attackers could gain SYSTEM-...
Aug 13, 2024This vulnerability in Comodo Internet Security Pro allows local attackers to escalate privileges from low-privileged user accounts to SYSTEM level by ...
Jul 29, 2024This vulnerability in Comodo Internet Security Pro allows local attackers to escalate privileges from low-privileged user accounts to SYSTEM level by ...
Jul 29, 2024This vulnerability in Azure Network Watcher VM Extension allows authenticated attackers to elevate privileges on affected virtual machines. Attackers ...
Jul 9, 2024This vulnerability allows local attackers to escalate privileges on systems running Poly Plantronics Hub by exploiting a symbolic link flaw in the Spo...
Jun 20, 2024This vulnerability allows attackers to execute arbitrary code on a victim's system by tricking them into opening a specially crafted Office document. ...
Jun 11, 2024This vulnerability in WithSecure Elements Endpoint Protection allows local attackers to escalate privileges to SYSTEM level by exploiting a symbolic l...
May 22, 2024This vulnerability in Avira Prime allows local attackers to escalate privileges from a low-privileged account to SYSTEM level by exploiting a symbolic...
May 22, 2024CVE-2024-30060 is an elevation of privilege vulnerability in Azure Monitor Agent that allows authenticated attackers to gain SYSTEM-level privileges o...
May 16, 2024This vulnerability allows attackers to elevate privileges on Windows systems by exploiting the PLUGScheduler scheduled task component. Attackers with ...
May 14, 2024This vulnerability allows local attackers with low-privileged access to escalate to root privileges by exploiting a symbolic link issue in Parallels D...
May 3, 2024This vulnerability allows local attackers to escalate privileges on systems running Intel Driver & Support Assistant (DSA) by exploiting a symbolic li...
May 3, 2024This vulnerability in G DATA Total Security allows local attackers to escalate privileges from low-privileged user accounts to SYSTEM level by exploit...
May 3, 2024CVE-2024-21447 is an elevation of privilege vulnerability in Windows Authentication that allows authenticated attackers to gain SYSTEM-level privilege...
Apr 9, 2024About CWE-59 (CWE-59)
Our database tracks 284 CVEs classified as CWE-59, with 13 rated critical and 203 rated high severity. The average CVSS score for CWE-59 vulnerabilities is 7.4.
External reference: View CWE-59 on MITRE CWE →
Monitor CWE-59 Vulnerabilities
Get alerted when new CWE-59 CVEs affect your infrastructure.
Start Monitoring Free