Threadlinqs IntelligenceStart free

Weakness · BaseCWE-59

CWE-59: Improper Link Resolution Before File Access ('Link Following')

Likelihood of exploit: MediumKEV-linkedBase

As of 2026-10-05, CWE-59 (Link Following) underlies 21 CVEs tracked by Threadlinqs, 4 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 38 tracked threats. MITRE rates its likelihood of exploit as Medium.

CVEs
21Mapped to CWE-59
CISA KEV
4Exploited in the wild
Critical
0CVSS v3 critical CVEs
Threats
38Tracked campaigns citing it
Likelihood
MediumMITRE likelihood of exploit

Last updated:

What is CWE-59?

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

CWE-59 is a base-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of Medium. Applicable platforms: Language: Not Language-Specific; Operating_System: Windows; Operating_System: Unix; Technology: Not Technology-Specific.

Source: MITRE CWE (CWE-59 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Confidentiality, Integrity, Access Control — Read Files or Directories, Modify Files or Directories, Bypass Protection Mechanism. An attacker may be able to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. If the files are used for a security mechanism then an attacker may be able to bypass the mechanism.
  • Other — Execute Unauthorized Code or Commands. Windows simple shortcuts, sometimes referred to as soft links, can be exploited remotely since a ".LNK" file can be uploaded like a normal file. This can enable remote execution.

Source: MITRE CWE, common consequences.

How CWE-59 is exploited in the wild

Threadlinqs maps 21 CVEs to CWE-59, published between 2025-01-15 and 2026-09-27. 4 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 1 is tied to ransomware campaigns. By CVSS v3 severity the set splits into 10 high, 5 medium, 3 low. The highest EPSS score in the set is 20.8% (CVE-2025-60710), the modelled probability of exploitation in the next 30 days. 38 tracked threats reference CWE-59 directly or through a CVE it covers; the most recent is “Multiple High-Severity Vulnerabilities in TeamViewer Client (CVE-2026-92370, CVE-2026-92368, CVE-2026-92369, CVE-2026-92371, CVE-2026-19743)” (2026-10-02). Affected products concentrate in Microsoft (7), AnyDesk (2), Red Hat (2), among 14 vendors in total.

Vulnerabilities (CVEs)

All 21 CVEs mapped to CWE-59, CISA KEV first, then by CVSS score.

Affected vendors

  • Microsoft — 7 CVEs
  • AnyDesk — 2 CVEs
  • Red Hat — 2 CVEs
  • 9001 — 1 CVE
  • Docker — 1 CVE
  • Himmelblau-Idm — 1 CVE
  • ImageMagick — 1 CVE
  • Simple-help — 1 CVE
  • TP-Link Systems Inc. — 1 CVE
  • moby — 1 CVE
  • nrwl — 1 CVE
  • opentofu — 1 CVE

Threat activity

38 tracked threats cite CWE-59; the 25 most recent are listed.

Mitigations

  • Architecture and Design / Separation of Privilege: Follow the principle of least privilege when assigning access rights to entities in a software system. Denying access to a file can prevent an attacker from replacing that file with a link to a sensitive file. Ensure good compartmentalization in the system to provide protected areas that can be trusted.

Source: MITRE CWE, potential mitigations.

Detection methods (MITRE CWE)

  • Automated Static Analysis - Binary or Bytecode (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Bytecode Weakness Analysis - including disassembler + source code weakness analysis
  • Manual Static Analysis - Binary or Bytecode (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Binary / Bytecode disassembler - then use manual analysis for vulnerabilities & anomalies
  • Dynamic Analysis with Automated Results Interpretation (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Web Application Scanner Web Services Scanner Database Scanners
  • Dynamic Analysis with Manual Results Interpretation (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Fuzz Tester Framework-based Fuzzer
  • Manual Static Analysis - Source Code (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Focused Manual Spotcheck - Focused manual analysis of source Manual Source Code Review (not inspections)
  • Automated Static Analysis - Source Code (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Source code Weakness Analyzer Context-configured Source Code Weakness Analyzer
  • Architecture or Design Review (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Formal Methods / Correct-By-Construction Cost effective for partial coverage: Inspection (IEEE 1028 standard) (can apply to requirements, design, source code, etc.)

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.