Skip to main content

About CWE-59

Attackers may read or overwrite unexpected files and bypass mechanisms that depend on those files. On Windows, uploaded shortcut files can enable remote execution.

MITRE name
Improper Link Resolution Before File Access ('Link Following')
Abstraction
Base: abstract, but detailed enough to infer detection and prevention methods
Status
Draft
Also known as
insecure temporary file, Zip Slip

Mitigations

  • +Apply least privilege to file access rights.
  • +Deny write access to locations where a file could be replaced by a link to a sensitive target.
  • +Compartmentalize the system so that protected areas can be trusted.

Detection
MITRE cites bytecode and binary analysis, scanners and fuzzers as cost effective for partial coverage.

CWE-59 Vulnerabilities

6 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-81963
Windows Update Stack Elevation of Privilege Vulnerability
Microsoft7.80.4%KEV2026-09-08
CVE-2026-41091
Microsoft Defender Elevation of Privilege Vulnerability
Microsoft7.80.4%KEV2026-05-20
CVE-2025-60710
Host Process for Windows Tasks Elevation of Privilege Vulnerability
Microsoft7.84.6%KEV2025-11-11
CVE-2025-48384
Git allows arbitrary code execution through broken config quoting
git8.14.2%KEV2025-07-08
CVE-2025-21391
Windows Storage Elevation of Privilege Vulnerability
Microsoft7.12.3%KEV2025-02-11
CVE-2023-36874
Windows Error Reporting Service Elevation of Privilege Vulnerability
Microsoft7.842.6%KEV2023-07-11

Most Affected Vendors

Frequently Asked Questions

What is CWE-59?→

CWE-59 is improper link resolution before file access, where a filename resolves through a symbolic link or shortcut to an unintended file.

Is Zip Slip part of CWE-59?→

MITRE lists Zip Slip as an alternate term. It notes Zip Slip is most often associated with relative path traversal (CWE-23) and link following (CWE-59).

How many exploited vulnerabilities are classified as CWE-59?→

This database lists 6 CVE records mapped to CWE-59 by their CVE Numbering Authority. 6 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 1 to known ransomware campaigns. Examples include CVE-2026-81963, CVE-2026-41091, CVE-2025-60710.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.