CWE-1386Base

Insecure Operation on Windows Junction / Mount Point

Incomplete in the CWE catalog · 15 CVEs mapped

15
CVEs mapped
6.3
Median CVSS
What it is

The product opens a file or directory, but it does not properly prevent the name from being associated with a junction or mount point to a destination that is outside of the intended control sphere.

Recent examples
6.3cvss
CVE-2026-41116

Dell Inventory Collector Client, versions prior to 13.8.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability

Dell Inventory Collector Client, versions prior to 13.8.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary File Write.

MEDIUMno explanation yet
0%
epss
8.8cvss
CVE-2025-58074

Privilege escalation during the installation of Norton Secure VPN via the Microsoft Store

A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store. A low-privilege user can replace files during the installation process, which may result in deletion of arbitrary files that can lead to elevation of privileges.

HIGHno explanation yet
0%
epss
6.6cvss
CVE-2024-36340

A junction point vulnerability within AMD uProf can allow a local low-privileged attacker to create junction points, potentially resulting in arbitrary file…

A junction point vulnerability within AMD uProf can allow a local low-privileged attacker to create junction points, potentially resulting in arbitrary file deletion or disclosure.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-1386
Abstraction
Base
Structure
Simple
Status
Incomplete
References (6)