Falhas do tipo CWE-59

820 resultados

Seguimento de links simbólicos (symlink)

A aplicação segue links simbólicos sem validação, permitindo que um atacante redirecione operações de arquivo para locais não autorizados. Isso pode resultar em leitura, modificação ou exclusão de arquivos sensíveis fora do diretório esperado.

Exemplo

Um servidor web processa uploads em /tmp/uploads/, mas não verifica se os caminhos são links simbólicos. Um atacante cria um symlink em /tmp/uploads/config que aponta para /etc/passwd, e a aplicação sobrescreve o arquivo de senhas do sistema.

Como mitigar

Use funções que resolvem caminhos canônicos (realpath em C, Path.toRealPath() em Java) antes de qualquer operação com arquivo, e implemente verificações de TOCTOU (time-of-check-time-of-use). Mantenha operações sensíveis em diretórios controlados com permissões restritivas e evite processar symlinks vindos de áreas com controle de usuário.

CVE-2022-31217HIGHDrive Composer Link Following Local Privilege Escalation VulnerabilityEPSS 0.3%CVE-2023-23558MEDIUMIn Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sentry-native-etserver EPSS 0.3%CVE-2023-42099HIGHIntel Driver & Support Assistant Link Following Local Privilege Escalation VulnerabilityEPSS 0.3%CVE-2023-52094HIGHAn updater link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to abuse the updater to delete an arbEPSS 0.3%CVE-2023-52091HIGHAn anti-spyware engine link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected EPSS 0.3%CVE-2023-52092HIGHA security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected instalEPSS 0.3%CVE-2023-52090HIGHA security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected instalEPSS 0.3%CVE-2025-58373MEDIUMRoo Code: Symlink-bypass of .rooignore can lead to unintended file disclosureEPSS 0.3%CVE-2023-52338HIGHA link following vulnerability in the Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could EPSS 0.3%CVE-2021-31843HIGHImproper access control vulnerability in McAfee ENS for WindowsEPSS 0.3%CVE-2024-7249HIGHComodo Firewall Link Following Local Privilege Escalation VulnerabilityEPSS 0.3%CVE-2025-34194HIGHVasion Print (formerly PrinterLogic) Local Privilege Escalation via Insecure Temporary File HandlingEPSS 0.3%CVE-2026-32212MEDIUMUniversal Plug and Play (upnp.dll) Information Disclosure VulnerabilityEPSS 0.3%CVE-2020-7282HIGHPrivilege Escalation vulnerability in McAfee Total Protection (MTP)EPSS 0.3%CVE-2024-12216HIGHArbitrary File Write via TarSlip in dmlc/gluon-cvEPSS 0.3%CVE-2024-7228MEDIUMAvast Free Antivirus Link Following Denial-of-Service VulnerabilityEPSS 0.3%CVE-2024-7235MEDIUMAVG AntiVirus Free Link Following Denial-of-Service VulnerabilityEPSS 0.3%CVE-2021-20197MEDIUMThere is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranEPSS 0.3%CVE-2022-31219HIGHDrive Composer Link Following Local Privilege Escalation VulnerabilityEPSS 0.3%CVE-2026-39243MEDIUMdecompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and file corruption. WheEPSS 0.3%