目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-59 在文件访问前对链接解析不恰当(链接跟随) 类漏洞列表 641

CWE-59 在文件访问前对链接解析不恰当(链接跟随) 类弱点 641 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-59 属于文件访问类漏洞,指程序在访问文件前未正确验证链接解析结果。攻击者常通过创建指向敏感资源的符号链接或快捷方式,诱导程序读取非预期文件,从而引发信息泄露或权限提升。开发者应避免直接使用用户输入的文件名,需在访问前校验最终解析路径,确保其位于预期的安全目录内,防止链接劫持风险。

MITRE CWE 官方描述
CWE:CWE-59 文件访问前链接解析不当('Link Following') 英文:产品尝试基于文件名访问文件,但未能正确防止该文件名标识解析到非预期资源的链接或快捷方式。
常见影响 (2)
Confidentiality, Integrity, Access Control Read Files or Directories, Modify Files or Directories, Bypass Protection Mechanism
An attacker may be able to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. If the files are used for a security mechanism then an attacker may be able to bypass the mechanism.
Other Execute Unauthorized Code or Commands
Windows simple shortcuts, sometimes referred to as soft links, can be exploited remotely since a ".LNK" file can be uploaded like a normal file. This can enable remote execution.
缓解措施 (1)
Architecture and Design Follow the principle of least privilege when assigning access rights to entities in a software system. Denying access to a file can prevent an attacker from replacing that file with a link to a sensitive file. Ensure good compartmentalization in the system to provide protected areas that can be trusted.
CVE ID 标题 CVSS 风险等级 Published
CVE-2024-43551 Microsoft Windows Storage Services 后置链接漏洞 — Windows 10 Version 1607 7.8 High 2024-10-08
CVE-2024-43501 Microsoft Windows Common Log File System Driver 后置链接漏洞 — Windows 10 Version 1507 7.8 High 2024-10-08
CVE-2024-38097 Microsoft Azure Monitor 后置链接漏洞 — Azure Monitor 7.1 High 2024-10-08
CVE-2024-27458 HP Hotkey Support 安全漏洞 — HP Hotkey Support 8.8 High 2024-10-07
CVE-2024-9341 Google Go 后置链接漏洞 5.4 Medium 2024-10-01
CVE-2024-8404 PaperCut NG/MF 安全漏洞 — PaperCut NG, PaperCut MF 7.8 High 2024-09-26
CVE-2024-45770 Performance Co-Pilot 后置链接漏洞 4.4 Medium 2024-09-19
CVE-2024-43470 Microsoft Azure 安全漏洞 — Azure Network Watcher VM Extension 7.3 High 2024-09-10
CVE-2024-38188 Microsoft Azure 后置链接漏洞 — Azure Network Watcher VM Extension 7.1 High 2024-09-10
CVE-2023-43078 Dell Client Platform和Dell Dock Firmware 后置链接漏洞 — Dell Client Platform, Dell Dock Firmware 6.7 Medium 2024-08-28
CVE-2024-5928 VIPRE Advanced Security 后置链接漏洞 — Advanced Security 7.8AI High AI 2024-08-21
CVE-2024-38098 Microsoft Azure Connected Machine Agent 后置链接漏洞 — Azure Connected Machine Agent 7.8 High 2024-08-13
CVE-2024-38084 Microsoft Office 后置链接漏洞 — Microsoft OfficePLUS 7.8 High 2024-08-13
CVE-2024-7252 Comodo Internet Security Pro 安全漏洞 — Internet Security Pro 7.8AI High AI 2024-07-29
CVE-2024-7251 Comodo Internet Security Pro 安全漏洞 — Internet Security Pro 7.8AI High AI 2024-07-29
CVE-2024-7250 Comodo Internet Security Pro 安全漏洞 — Internet Security Pro 7.8AI High AI 2024-07-29
CVE-2024-7249 Comodo Firewall 安全漏洞 — Firewall 7.8AI High AI 2024-07-29
CVE-2024-38081 Microsoft Visual Studio和Microsoft .NET 安全漏洞 — Microsoft Visual Studio 2022 version 17.4 7.3 High 2024-07-09
CVE-2024-35261 Microsoft Azure 安全漏洞 — Azure Network Watcher VM Extension 7.8 High 2024-07-09
CVE-2024-38022 Microsoft Windows 安全漏洞 — Windows 10 Version 1809 7.0 High 2024-07-09
CVE-2024-38013 Microsoft Windows Server 安全漏洞 — Windows 10 Version 1809 6.7 Medium 2024-07-09
CVE-2024-6147 Poly Plantronics Hub 安全漏洞 — Plantronics Hub 7.8AI High AI 2024-06-20
CVE-2024-5742 Nano 安全漏洞 6.7 Medium 2024-06-12
CVE-2024-35254 Microsoft Azure Monitor 后置链接漏洞 — Azure Monitor 7.1 High 2024-06-11
CVE-2024-35253 Microsoft Azure 后置链接漏洞 — Azure File Sync 4.4 Medium 2024-06-11
CVE-2024-30104 Microsoft Office 后置链接漏洞 — Microsoft 365 Apps for Enterprise 7.8 High 2024-06-11
CVE-2024-30093 Microsoft Windows Storage 后置链接漏洞 — Windows 10 Version 1507 7.3 High 2024-06-11
CVE-2024-30065 Microsoft Windows Themes 后置链接漏洞 — Windows 10 Version 1507 5.5 Medium 2024-06-11
CVE-2024-30076 Microsoft Windows Container Manager Service 后置链接漏洞 — Windows 10 Version 1607 6.8 Medium 2024-06-11
CVE-2024-35235 OpenPrinting CUPS 安全漏洞 — cups 4.4 Medium 2024-06-11

CWE-59(在文件访问前对链接解析不恰当(链接跟随)) 是常见的弱点类别,本平台收录该类弱点关联的 641 条 CVE 漏洞。