CWE-59: CWE-59

287
Total CVEs
13
Critical
206
High
7.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
30
2025
90
2024
70
2023
40
2022
20

Top Affected Vendors

1 Microsoft 75
2 Apple 24
3 Trendmicro 13
4 Canonical 6
5 Dell 6
6 Google 5
7 Mcafee 4
8 Avast 4
9 Debian 4
10 Malwarebytes 4

All CWE-59 CVEs (287)

CVE-2023-36399
7.1

CVE-2023-36399 is an elevation of privilege vulnerability in Windows Storage that allows authenticated attackers to gain SYSTEM-level privileges on af...

Nov 14, 2023
CVE-2023-36876
7.1

This vulnerability allows an authenticated attacker to elevate privileges on affected Windows systems by exploiting a flaw in the Reliability Analysis...

Aug 8, 2023
CVE-2023-35347
7.1

This vulnerability allows attackers to elevate privileges on Windows systems by exploiting a flaw in the Microsoft Install Service. Attackers with loc...

Jul 11, 2023
CVE-2023-27469
7.1

This vulnerability in Malwarebytes Anti-Exploit allows attackers to delete arbitrary files or cause denial of service by sending specially crafted ALP...

Jun 30, 2023
CVE-2022-34292
7.1

This vulnerability in Docker Desktop for Windows allows attackers to overwrite arbitrary files through a symlink attack on the hyperv/create dockerBac...

Apr 27, 2023
CVE-2023-28222
7.1

This Windows kernel vulnerability allows attackers to elevate privileges from user mode to kernel mode, potentially gaining SYSTEM-level access. It af...

Apr 11, 2023
CVE-2022-32450
7.1

This vulnerability in AnyDesk 7.0.9 allows a local user to escalate privileges to SYSTEM via a symbolic link attack. The software writes chat-room dat...

Jul 18, 2022
CVE-2022-26659
7.1

This vulnerability allows attackers to overwrite administrator-writable files on Windows systems by exploiting a symlink vulnerability in Docker Deskt...

Mar 25, 2022
CVE-2022-21997
7.1

This vulnerability allows attackers to elevate privileges on Windows systems by exploiting the Print Spooler service. Attackers could gain SYSTEM-leve...

Feb 9, 2022
CVE-2021-41057
7.1

This vulnerability in WIBU CodeMeter Runtime allows local attackers to overwrite arbitrary files via a crafted symbolic link attack. It affects system...

Nov 14, 2021
CVE-2021-1091
7.1

This vulnerability in NVIDIA GPU Display drivers for Windows allows unprivileged users to create hard links that trick the driver into overwriting pro...

Jul 22, 2021
CVE-2021-26866
7.1

This vulnerability allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by exploiting a flaw in the Windows Update Servic...

Mar 11, 2021
CVE-2020-16851
7.1

This CVE describes a local privilege escalation vulnerability in OneDrive for Windows Desktop where improper symbolic link handling allows an attacker...

Sep 11, 2020
CVE-2020-16853
7.1

This CVE describes a privilege escalation vulnerability in OneDrive for Windows Desktop where improper handling of symbolic links allows an attacker t...

Sep 11, 2020
CVE-2024-30033
7.0

This vulnerability in Windows Search Service allows an authenticated attacker to execute arbitrary code with SYSTEM privileges, leading to local privi...

May 14, 2024
CVE-2023-0652
7.0

This vulnerability allows local attackers to escalate privileges by exploiting hardlink creation during the Cloudflare WARP client repair process. Att...

Apr 6, 2023
CVE-2022-21919
7.0

CVE-2022-21919 is an elevation of privilege vulnerability in the Windows User Profile Service that allows an authenticated attacker to gain SYSTEM-lev...

Jan 11, 2022
CVE-2021-26426
7.0

CVE-2021-26426 is an elevation of privilege vulnerability in Windows User Account Profile Picture handling that allows authenticated attackers to exec...

Aug 12, 2021
CVE-2021-26862
7.0

CVE-2021-26862 is a Windows Installer elevation of privilege vulnerability that allows authenticated attackers to execute arbitrary code with SYSTEM p...

Mar 11, 2021
CVE-2025-67124
6.8

This vulnerability in miniserve allows attackers to overwrite arbitrary files outside the intended upload directory through a TOCTOU (Time-of-Check Ti...

Jan 23, 2026
CVE-2026-23893
6.8

openCryptoki versions 2.3.2+ are vulnerable to symlink attacks when running with elevated privileges. Token-group users can plant symbolic links in gr...

Jan 22, 2026
CVE-2025-5718
6.8

This CVE describes a privilege escalation vulnerability in the ACAP Application framework through symlink attacks. It affects Axis devices configured ...

Nov 11, 2025
CVE-2024-30076
6.8

This vulnerability allows an authenticated attacker to escalate privileges within Windows Container Manager Service. Attackers could gain SYSTEM-level...

Jun 11, 2024
CVE-2025-24918
6.7

This CVE describes a link following vulnerability in Intel Server Configuration Utility and Server Firmware Update Utility that allows authenticated l...

Nov 11, 2025
CVE-2025-43726
6.7

Dell Alienware Command Center versions before 5.10.2.0 contain a link following vulnerability that allows local attackers with low privileges to eleva...

Sep 2, 2025
CVE-2025-29983
6.7

Dell Trusted Device versions before 7.0.3.0 contain a link following vulnerability that allows local attackers with low privileges to elevate their pr...

Apr 15, 2025
CVE-2024-5742
6.7

This vulnerability in GNU Nano allows local privilege escalation through insecure temporary file handling. When Nano is killed during editing, it crea...

Jun 12, 2024
CVE-2026-21419
6.6

Dell Display and Peripheral Manager versions before 2.2 contain a symbolic link vulnerability that allows local attackers to escalate privileges. Atta...

Feb 9, 2026
CVE-2025-15324
6.6

CVE-2025-15324 is a documentation issue in Tanium Engage that could lead to improper link resolution. This vulnerability affects organizations using T...

Feb 5, 2026
CVE-2025-46636
6.6

Dell Encryption versions before 11.12.1 contain a link following vulnerability that allows local low-privileged attackers to manipulate symbolic links...

Dec 9, 2025
CVE-2025-57749
6.5

A symlink traversal vulnerability in n8n's Read/Write File node allows attackers to bypass directory restrictions. By creating symbolic links, attacke...

Aug 20, 2025
CVE-2025-43252
6.5

This macOS vulnerability allows malicious websites to access sensitive user data by exploiting symlink resolution. It affects macOS users who visit co...

Jul 30, 2025
CVE-2026-24047
6.3

This vulnerability in Backstage's @backstage/backend-plugin-api allows attackers to bypass path traversal protections via symlink chains and dangling ...

Jan 21, 2026
CVE-2025-68146
6.3

A Time-of-Check-Time-of-Use (TOCTOU) race condition in filelock versions before 3.20.1 allows local attackers to corrupt or truncate arbitrary user fi...

Dec 16, 2025
CVE-2025-14693
6.2

This vulnerability in Ugreen DH2100+ network-attached storage devices allows attackers with physical access to exploit symlink following in the USB Ha...

Dec 15, 2025
CVE-2025-62364
6.2

This Local File Inclusion vulnerability in text-generation-webui allows unauthenticated attackers to read arbitrary files on the server by uploading s...

Oct 13, 2025
CVE-2025-3908
6.2

This vulnerability allows a local attacker on Linux systems to create symbolic links that trick OpenVPN's configuration initialization tool into chang...

May 19, 2025
CVE-2025-69429
6.1

The ORICO NAS CD3510 (version V1.9.12 and below) contains an Incorrect Symlink Follow vulnerability that allows attackers with physical access to a US...

Feb 3, 2026
CVE-2025-69430
6.1

An incorrect symlink follow vulnerability in Yottamaster NAS devices allows attackers with physical USB drive access to read and modify the NAS intern...

Feb 3, 2026
CVE-2025-69431
6.1

This vulnerability in ZSPACE Q2C NAS devices allows attackers to bypass security controls by creating a malicious symbolic link on a USB drive. When t...

Feb 3, 2026
CVE-2025-22247
6.1

CVE-2025-22247 is an insecure file handling vulnerability in VMware Tools that allows non-administrative users on a guest VM to manipulate local files...

May 12, 2025
CVE-2025-32817
6.1

This vulnerability in SonicWall Connect Tunnel Windows client allows attackers to overwrite arbitrary files through improper link resolution. This cou...

Apr 16, 2025
CVE-2024-36306
6.1

A link following vulnerability in Trend Micro Apex One and Apex One as a Service Damage Cleanup Engine allows a local attacker with low-privileged cod...

Jun 10, 2024
CVE-2025-21347
6.0

This vulnerability in Windows Deployment Services allows attackers to cause a denial of service by sending specially crafted packets to vulnerable ser...

Feb 11, 2025
CVE-2025-21188
6.0

This vulnerability in Azure Network Watcher VM Extension allows authenticated users with VM-level access to elevate privileges to root/system level on...

Feb 11, 2025
CVE-2026-23563
5.7

This vulnerability allows a low-privileged local attacker on Windows systems to delete protected system files by exploiting improper link resolution i...

Jan 29, 2026
CVE-2020-3432
5.6

This vulnerability in Cisco AnyConnect Secure Mobility Client for Mac OS allows authenticated local attackers to corrupt files via symlink attacks. At...

Feb 12, 2025
CVE-2026-2490
5.5

This vulnerability in RustDesk Client for Windows allows local attackers with low-privileged code execution to read arbitrary files on the system by e...

Feb 20, 2026
CVE-2025-15313
5.5

CVE-2025-15313 is an arbitrary file deletion vulnerability in Tanium EUSS that allows authenticated attackers to delete files on the server. This affe...

Feb 10, 2026
CVE-2025-15314
5.5

CVE-2025-15314 is an arbitrary file deletion vulnerability in Tanium's end-user-cx component that allows authenticated attackers to delete files on af...

Feb 10, 2026

About CWE-59 (CWE-59)

Our database tracks 287 CVEs classified as CWE-59, with 13 rated critical and 206 rated high severity. The average CVSS score for CWE-59 vulnerabilities is 7.4.

External reference: View CWE-59 on MITRE CWE →

Monitor CWE-59 Vulnerabilities

Get alerted when new CWE-59 CVEs affect your infrastructure.

Start Monitoring Free