VariantIncomplete
CWE-64Windows Shortcut Following (.LNK)
Category: other
Description
The product, when opening a file or directory, does not sufficiently handle when the file is a Windows shortcut (.LNK) whose target is outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.
Common consequences· 1
- Confidentiality / Integrity — Read Files or Directories, Modify Files or DirectoriesThe shortcut (file with the .lnk extension) can permit an attacker to read/write a file that they originally did not have permissions to access.
Potential mitigations· 1
- [Architecture and Design]
References
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.