CWE-59: CWE-59
Yearly Trend
Top Affected Vendors
All CWE-59 CVEs (286)
This vulnerability allows a local user on a Windows system to escalate privileges to SYSTEM level and delete arbitrary files, potentially causing deni...
Feb 10, 2021This vulnerability in Google Chrome's Cryptohome component allows a local attacker to escalate operating system privileges through a specially crafted...
Feb 9, 2021This CVE-2020-16939 is a Windows Group Policy privilege escalation vulnerability where improper access checks allow authenticated attackers to run pro...
Oct 16, 2020Aquarius Desktop 3.0.069 for macOS contains an insecure file handling vulnerability where the application follows symbolic links when creating support...
Dec 3, 2025CVE-2022-22262 is a local privilege escalation vulnerability in ROG Live Service where improper symbolic link handling allows unauthenticated local at...
Mar 1, 2022CVE-2025-8959 is a symlink attack vulnerability in HashiCorp's go-getter library that allows attackers to read files outside the intended download dir...
Aug 15, 2025CVE-2025-25185 is a path traversal vulnerability in GPT Academic that allows attackers to read arbitrary files on the server by exploiting improper sy...
Mar 3, 2025HashiCorp's go-slug library is vulnerable to a zip-slip attack when extracting tar archives with non-existing user-provided paths. This allows attacke...
Jan 21, 2025This macOS vulnerability allows websites to access sensitive user data through improper symlink resolution. It affects macOS Monterey, Ventura, and So...
Oct 25, 2023This vulnerability allows attackers to access sensitive system configuration files via path traversal in the TechView LA-5570 Wireless Gateway. Attack...
Aug 25, 2023A local privilege escalation vulnerability in cloudflared's Windows 32-bit installer allows attackers without administrative rights to delete or repla...
Mar 21, 2023This vulnerability in the Iris web framework allows attackers to perform directory traversal attacks during file uploads. By manipulating file names i...
Dec 24, 2021This vulnerability in Huawei smartphones allows attackers to access and modify files through improper symlink handling during backup restoration. Atta...
Oct 28, 2021This vulnerability in the Rust tar crate allows attackers to create arbitrary directories outside the intended extraction path when processing TAR arc...
Aug 10, 2021This CVE describes a remote code execution vulnerability in Microsoft Windows shortcut (.LNK) file processing. An attacker can execute arbitrary code ...
Aug 14, 2019A local privilege escalation vulnerability in Tencent iOA for Windows allows authenticated local users to execute programs with elevated privileges by...
Feb 23, 2026This vulnerability in MSP360 Free Backup allows local attackers to escalate privileges to SYSTEM by exploiting a link following flaw in the restore fu...
Dec 23, 2025Dell Encryption versions before 11.12.1 contain a link-following vulnerability that allows local attackers to escalate privileges. This affects system...
Dec 9, 2025This vulnerability allows a local malicious user to exploit improper link resolution in Dell Encryption and Dell Security Management Server, potential...
Jul 30, 2025This vulnerability allows an authorized attacker to exploit improper link resolution in Windows Performance Recorder, enabling local denial of service...
Jul 8, 2025This vulnerability allows an authorized attacker on a Windows system to exploit improper link resolution in the Windows Recovery Driver, enabling loca...
Jun 10, 2025This Windows Installer vulnerability allows attackers to elevate privileges on affected systems by exploiting improper handling of symbolic links. It ...
Jan 14, 2025This vulnerability in Foxit PDF Reader allows local attackers to escalate privileges from low-privileged user accounts to SYSTEM level by exploiting a...
Dec 30, 2024CVE-2024-22038 is a vulnerability in obs-scm-bridge that allows attackers to leak sensitive information or cause denial of service by creating special...
Nov 28, 2024This vulnerability in Azure Network Watcher VM Agent allows authenticated attackers to elevate privileges on affected virtual machines. Attackers coul...
Sep 10, 2024This vulnerability allows attackers to elevate privileges on systems running affected .NET, .NET Framework, or Visual Studio installations. An authent...
Jul 9, 2024This vulnerability allows an authenticated attacker to gain SYSTEM-level privileges on Windows servers running the File Server Resource Management Ser...
Apr 9, 2024This vulnerability in Azure Connected Machine Agent allows an authenticated attacker to elevate privileges on affected systems. Attackers could gain S...
Dec 12, 2023CVE-2022-38604 is an arbitrary file deletion vulnerability in Wacom tablet drivers for Windows. Attackers can delete arbitrary files on affected syste...
Apr 11, 2023This vulnerability in Trend Micro Antivirus for Mac allows attackers with low-level system privileges to create symbolic links that can lead to privil...
Apr 9, 2022This vulnerability in Apport's read_file() function allows local attackers to read arbitrary files by exploiting symbolic links or FIFOs. When used by...
Jun 12, 2021CVE-2021-32555 is a path traversal vulnerability in Apport's read_file() function that follows symbolic links and opens FIFOs, potentially exposing se...
Jun 12, 2021This vulnerability in Apport's read_file() function allows local attackers to read arbitrary files by exploiting symbolic links or FIFOs. It affects U...
Jun 12, 2021This vulnerability in Apport's read_file() function allows local attackers to read arbitrary files by exploiting symbolic links or FIFOs. It affects U...
Jun 12, 2021This vulnerability in Apport's read_file() function allows local attackers to read arbitrary files via symbolic link or FIFO manipulation. When exploi...
Jun 12, 2021This CVE describes a privilege escalation vulnerability in GitHub Enterprise Server where authenticated enterprise administrators could gain root SSH ...
Nov 10, 2025This vulnerability in SonicWall NetExtender Windows client allows attackers to manipulate file paths through improper link resolution, potentially lea...
Apr 10, 2025CVE-2024-57728 is a path traversal vulnerability in SimpleHelp remote support software that allows authenticated admin users to upload arbitrary files...
Jan 15, 2025This vulnerability allows attackers to manipulate symbolic links to access arbitrary files on macOS systems running vulnerable versions of HYPR Workfo...
Jan 16, 2024Zed code editor versions before 0.225.9 have a symlink escape vulnerability that allows reading and writing files outside the project directory when s...
Feb 26, 2026A local privilege escalation vulnerability in Fortinet FortiClient for Windows allows low-privileged attackers to write arbitrary files with elevated ...
Feb 10, 2026A path traversal vulnerability in SIR 1.0.3 and earlier allows authenticated non-admin local users to overwrite system files by manipulating backup fi...
Jun 26, 2025This vulnerability in the gluon-cv library allows attackers to overwrite arbitrary files on a victim's system through a TarSlip attack. When the Image...
Mar 20, 2025This CVE describes a local privilege escalation vulnerability in Microsoft Windows where an attacker with existing access can exploit improper link re...
Mar 11, 2025This vulnerability allows an authenticated attacker to exploit Windows Setup cleanup processes to gain SYSTEM privileges on affected systems. It affec...
Feb 11, 2025This Windows Storage Elevation of Privilege vulnerability allows authenticated attackers to gain SYSTEM-level privileges by exploiting improper handli...
Feb 11, 2025This vulnerability allows an authenticated attacker with local access to a virtual machine to elevate privileges to SYSTEM level through the Azure Net...
Sep 10, 2024This CVE describes an elevation of privilege vulnerability in Azure Monitor Agent that allows authenticated attackers to gain higher privileges on aff...
Jun 11, 2024This vulnerability allows an attacker to exploit improper link resolution in Zscaler Client Connector on macOS, enabling them to overwrite system file...
May 2, 2024CVE-2023-36399 is an elevation of privilege vulnerability in Windows Storage that allows authenticated attackers to gain SYSTEM-level privileges on af...
Nov 14, 2023About CWE-59 (CWE-59)
Our database tracks 286 CVEs classified as CWE-59, with 13 rated critical and 205 rated high severity. The average CVSS score for CWE-59 vulnerabilities is 7.4.
External reference: View CWE-59 on MITRE CWE →
Monitor CWE-59 Vulnerabilities
Get alerted when new CWE-59 CVEs affect your infrastructure.
Start Monitoring Free