Back to Labs
Weakness (CWE)

CWE-59

Improper Link Resolution Before File Access ('Link Following')

About

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Common consequences

  • Confidentiality, Integrity, Access Control → Read Files or Directories, Modify Files or Directories, Bypass Protection Mechanism
  • Other → Execute Unauthorized Code or Commands

Mitigations

  • Architecture and Design: Follow the principle of least privilege when assigning access rights to entities in a software system. Denying access to a file can prevent an attacker from replacing that file with a link to a sensitive file. Ensure good compartmentalization in the system to provide protected areas that can be trusted.

CVEs with this weakness

Frequently asked questions

What is CWE-59?

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

How likely is CWE-59 to be exploited?

MITRE rates the likelihood of exploit for CWE-59 as medium.

Which platforms does CWE-59 affect?

CWE-59 has been observed on: Windows, Unix, Not Technology-Specific.

How many CVEs does Rainforest track for CWE-59?

Rainforest Labs currently tracks 1 published CVEs mapped to CWE-59. They are listed on this page.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.