CWE-59: CWE-59

284
Total CVEs
13
Critical
203
High
7.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
30
2025
90
2024
70
2023
40
2022
20

Top Affected Vendors

1 Microsoft 75
2 Apple 24
3 Trendmicro 13
4 Dell 6
5 Canonical 6
6 Google 4
7 Avast 4
8 Malwarebytes 4
9 Tanium 3
10 Fedoraproject 3

All CWE-59 CVEs (284)

CVE-2023-42942
7.8

This CVE describes a privilege escalation vulnerability in Apple operating systems where improper symlink handling allows malicious applications to ga...

Feb 21, 2024
CVE-2023-52090
7.8

This CVE describes a link following vulnerability in Trend Micro Apex One security agent that allows a local attacker to escalate privileges on affect...

Jan 23, 2024
CVE-2023-52092
7.8

This CVE describes a link following vulnerability in Trend Micro Apex One security agent that allows a local attacker to escalate privileges on affect...

Jan 23, 2024
CVE-2023-52094
7.8

This vulnerability in Trend Micro Apex One agent allows a local attacker with low-privileged code execution to abuse the updater to delete arbitrary f...

Jan 23, 2024
CVE-2023-52338
7.8

This CVE describes a link following vulnerability in Trend Micro Deep Security 20.0 and Cloud One - Endpoint and Workload Security Agent that allows l...

Jan 23, 2024
CVE-2024-20656
7.8

This CVE describes an elevation of privilege vulnerability in Visual Studio that allows authenticated attackers to gain SYSTEM-level privileges on aff...

Jan 9, 2024
CVE-2023-43116
7.8

This vulnerability allows a malicious buildkite-agent user to change ownership of arbitrary directories via a symbolic link attack in the fix-buildkit...

Dec 22, 2023
CVE-2023-36391
7.8

CVE-2023-36391 is a local privilege escalation vulnerability in Windows Local Security Authority Subsystem Service (LSASS) that allows authenticated a...

Dec 12, 2023
CVE-2023-43590
7.8

This vulnerability in Zoom Rooms for macOS allows authenticated users with local access to escalate privileges through improper link following. Attack...

Nov 15, 2023
CVE-2023-36705
7.8

This Windows Installer vulnerability allows attackers to elevate privileges on affected systems by exploiting improper handling of file operations. It...

Nov 14, 2023
CVE-2023-36047
7.8

This Windows authentication vulnerability allows attackers to elevate privileges on affected systems. An authenticated attacker could exploit this to ...

Nov 14, 2023
CVE-2023-36737
7.8

This vulnerability allows an authenticated attacker with local access to an Azure virtual machine to elevate privileges to SYSTEM level through the Ne...

Oct 10, 2023
CVE-2023-36711
7.8

This vulnerability in the Windows Runtime C++ Template Library allows an authenticated attacker to execute arbitrary code with elevated privileges on ...

Oct 10, 2023
CVE-2023-36723
7.8

This vulnerability in Windows Container Manager Service allows an authenticated attacker to gain SYSTEM-level privileges by exploiting improper link r...

Oct 10, 2023
CVE-2019-13689
7.8

This critical vulnerability in ChromeOS allowed attackers to perform arbitrary read/write operations via malicious files, potentially leading to syste...

Aug 25, 2023
CVE-2023-36874
7.8

CVE-2023-36874 is a local privilege escalation vulnerability in the Windows Error Reporting Service that allows authenticated attackers to gain SYSTEM...

Jul 11, 2023
CVE-2023-35342
7.8

This vulnerability allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by exploiting a flaw in Windows Image Acquisition...

Jul 11, 2023
CVE-2023-35320
7.8

This is a Windows privilege escalation vulnerability in the Connected User Experiences and Telemetry service. It allows authenticated attackers to gai...

Jul 11, 2023
CVE-2023-32053
7.8

This Windows Installer vulnerability allows attackers to gain SYSTEM-level privileges by exploiting improper handling of symbolic links. It affects Wi...

Jul 11, 2023
CVE-2023-32056
7.8

This vulnerability allows an authenticated attacker to elevate privileges on Windows Server Update Service (WSUS) servers. Attackers could gain SYSTEM...

Jul 11, 2023
CVE-2023-32012
7.8

This vulnerability allows an authenticated attacker to gain SYSTEM-level privileges on Windows systems by exploiting a flaw in the Container Manager S...

Jun 14, 2023
CVE-2023-33865
7.8

CVE-2023-33865 is a local privilege escalation vulnerability in RenderDoc that allows attackers to gain elevated privileges via symlink attacks. It af...

Jun 7, 2023
CVE-2023-2939
7.8

This vulnerability allows a local attacker on Windows systems to escalate privileges by exploiting insufficient data validation in Google Chrome's ins...

May 30, 2023
CVE-2023-27529
7.8

This vulnerability in Wacom Tablet Driver installer for macOS allows arbitrary code execution with root privileges when a user is tricked into running...

May 25, 2023
CVE-2023-29343
7.8

This vulnerability in Sysinternals Sysmon for Windows allows attackers to elevate privileges from a low-privileged user to SYSTEM level. It affects Wi...

May 9, 2023
CVE-2023-28892
7.8

This vulnerability in Malwarebytes AdwCleaner 8.4.0 allows non-admin users to escalate privileges to SYSTEM by exploiting an insecure file deletion op...

Mar 29, 2023
CVE-2023-26088
7.8

This vulnerability in Malwarebytes allows attackers to delete arbitrary files via symbolic link exploitation in the local quarantine system. It affect...

Mar 23, 2023
CVE-2023-24930
7.8

This vulnerability in Microsoft OneDrive for macOS allows an attacker to gain elevated privileges on the system. An authenticated attacker could explo...

Mar 14, 2023
CVE-2023-25145
7.8

This CVE describes a local privilege escalation vulnerability in Trend Micro Apex One's scanning function. An attacker with low-privileged access can ...

Mar 10, 2023
CVE-2023-25148
7.8

This vulnerability in Trend Micro Apex One allows a local attacker with low-privileged access to escalate privileges by manipulating file links. Attac...

Mar 10, 2023
CVE-2021-25261
7.8

This CVE describes a local privilege escalation vulnerability in Yandex Browser for Windows. A local attacker with low privileges can manipulate symbo...

Jun 15, 2022
CVE-2022-28225
7.8

This vulnerability allows a local attacker with low privileges to execute arbitrary code with SYSTEM privileges by manipulating symbolic links during ...

Jun 15, 2022
CVE-2022-31216
7.8

This vulnerability in ABB Drive Composer allows low-privileged users to create and write arbitrary files anywhere on the file system with SYSTEM privi...

Jun 15, 2022
CVE-2022-31218
7.8

This vulnerability in ABB Drive Composer allows low-privileged users to create and write arbitrary files anywhere on the file system with SYSTEM privi...

Jun 15, 2022
CVE-2022-26704
7.8

This macOS vulnerability allows malicious applications to bypass symlink validation and gain elevated privileges. It affects macOS Monterey versions b...

May 26, 2022
CVE-2022-30523
7.8

This vulnerability in Trend Micro Password Manager allows a local attacker with low privileges to delete arbitrary folder contents with SYSTEM-level p...

May 16, 2022
CVE-2021-27116
7.8

This vulnerability in Beego's MemProf function allows local attackers to perform symlink attacks, potentially overwriting arbitrary files on the syste...

Apr 5, 2022
CVE-2022-24680
7.8

This vulnerability allows a local attacker with low-privileged code execution to escalate privileges by creating mount points and deleting arbitrary f...

Feb 24, 2022
CVE-2021-44730
7.8

CVE-2021-44730 is a privilege escalation vulnerability in snapd where improper validation of the snap-confine binary location allows local attackers t...

Feb 17, 2022
CVE-2022-21895
7.8

This vulnerability allows an authenticated attacker to exploit the Windows User Profile Service to gain SYSTEM privileges on affected Windows systems....

Jan 11, 2022
CVE-2021-43238
7.8

This vulnerability allows an authenticated attacker to execute code with SYSTEM privileges on Windows systems by exploiting improper link resolution i...

Dec 15, 2021
CVE-2021-37969
7.8

This vulnerability allows a remote attacker to escalate privileges on Windows systems running vulnerable versions of Google Chrome. By tricking a user...

Oct 8, 2021
CVE-2020-9452
7.8

This vulnerability in Acronis True Image 2020 allows unprivileged users to escalate privileges to SYSTEM by exploiting improper access controls in the...

May 25, 2021
CVE-2021-23872
7.8

This CVE describes a local privilege escalation vulnerability in McAfee Total Protection's File Lock component. A local user can manipulate symbolic l...

May 12, 2021
CVE-2020-28007
7.8

CVE-2020-28007 is a privilege escalation vulnerability in Exim mail servers where an attacker can create symbolic or hard links in the log directory t...

May 6, 2021
CVE-2021-28321
7.8

CVE-2021-28321 is an elevation of privilege vulnerability in Microsoft's Diagnostics Hub Standard Collector Service. It allows authenticated attackers...

Apr 13, 2021
CVE-2021-30463
7.8

CVE-2021-30463 is a local privilege escalation vulnerability in VestaCP that allows attackers to gain admin privileges by exploiting symlink creation ...

Apr 8, 2021
CVE-2020-7346
7.8

A local privilege escalation vulnerability in McAfee Data Loss Prevention (DLP) for Windows allows low-privileged attackers to load arbitrary DLLs via...

Mar 23, 2021
CVE-2021-26889
7.8

CVE-2021-26889 is an elevation of privilege vulnerability in the Windows Update Stack that allows authenticated attackers to execute arbitrary code wi...

Mar 11, 2021
CVE-2021-3310
7.8

Western Digital My Cloud OS 5 devices before version 5.10.122 have a symbolic link following vulnerability in SMB and AFP shares. This allows attacker...

Mar 10, 2021

About CWE-59 (CWE-59)

Our database tracks 284 CVEs classified as CWE-59, with 13 rated critical and 203 rated high severity. The average CVSS score for CWE-59 vulnerabilities is 7.4.

External reference: View CWE-59 on MITRE CWE →

Monitor CWE-59 Vulnerabilities

Get alerted when new CWE-59 CVEs affect your infrastructure.

Start Monitoring Free