Link Following (CWE-59)
CWE-59 covers products that access a file by name without preventing that name from resolving through a link or shortcut to an unintended resource. MITRE calls link following a multi-factor issue involving permissions, filename predictability and race conditions. Zip Slip is listed as an alternate term for archive extraction cases.
About CWE-59
Attackers may read or overwrite unexpected files and bypass mechanisms that depend on those files. On Windows, uploaded shortcut files can enable remote execution.
Mitigations
- +Apply least privilege to file access rights.
- +Deny write access to locations where a file could be replaced by a link to a sensitive target.
- +Compartmentalize the system so that protected areas can be trusted.
Detection
MITRE cites bytecode and binary analysis, scanners and fuzzers as cost effective for partial coverage.
CWE-59 Vulnerabilities
6 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack Elevation of Privilege Vulnerability | Microsoft | 7.8 | 0.4% | KEV | 2026-09-08 |
| CVE-2026-41091 | Microsoft Defender Elevation of Privilege Vulnerability | Microsoft | 7.8 | 0.4% | KEV | 2026-05-20 |
| CVE-2025-60710 | Host Process for Windows Tasks Elevation of Privilege Vulnerability | Microsoft | 7.8 | 4.6% | KEV | 2025-11-11 |
| CVE-2025-48384 | Git allows arbitrary code execution through broken config quoting | git | 8.1 | 4.2% | KEV | 2025-07-08 |
| CVE-2025-21391 | Windows Storage Elevation of Privilege Vulnerability | Microsoft | 7.1 | 2.3% | KEV | 2025-02-11 |
| CVE-2023-36874 | Windows Error Reporting Service Elevation of Privilege Vulnerability | Microsoft | 7.8 | 42.6% | KEV | 2023-07-11 |
Most Affected Vendors
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-59?→
CWE-59 is improper link resolution before file access, where a filename resolves through a symbolic link or shortcut to an unintended file.
Is Zip Slip part of CWE-59?→
MITRE lists Zip Slip as an alternate term. It notes Zip Slip is most often associated with relative path traversal (CWE-23) and link following (CWE-59).
How many exploited vulnerabilities are classified as CWE-59?→
This database lists 6 CVE records mapped to CWE-59 by their CVE Numbering Authority. 6 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 1 to known ransomware campaigns. Examples include CVE-2026-81963, CVE-2026-41091, CVE-2025-60710.
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.