The product opens a file or directory, but it does not properly prevent the name from being associated with a junction or mount point to a destination that is outside of the intended control sphere.
Volume of CVEs assigned to CWE-1386 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-58074HIGH A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store. A low-privilege user can replace files during the installation pro | May 4, 2026 | 8.8 | 35 | NO | NO |
CVE-2024-7400HIGH The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file on the Windows operating system to delete files without hav | Sep 27, 2024 | 8.5 | 28 | NO | NO |
CVE-2026-41116MEDIUM Dell Inventory Collector Client, versions prior to 13.8.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with l | Jun 9, 2026 | 6.3 | 25 | NO | NO |
CVE-2023-5834HIGH HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauthorized file system writes. Fixe | Oct 27, 2023 | 7.8 | 22 | NO | NO |
CVE-2023-32474MEDIUM
Dell Display Manager application, version 2.1.1.17 and prior, contain an insecure operation on windows junction/mount point. A local malicious user could potentially exploit this | Feb 6, 2024 | 6.6 | 21 | NO | NO |
CVE-2023-32454HIGH
DUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerability. A local malicious standard user could exploit the vulnerability | Feb 6, 2024 | 7.1 | 20 | NO | NO |
CVE-2023-28065HIGH
Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious | Jun 23, 2023 | 7.3 | 20 | NO | NO |
CVE-2022-42291MEDIUM
NVIDIA GeForce Experience contains a vulnerability in the installer, where a user installing the NVIDIA GeForce Experience software may inadvertently delete data from a linked loc | Feb 7, 2023 | 5.5 | 20 | NO | NO |
CVE-2023-40623HIGH SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and link it to a directory with operat | Sep 12, 2023 | 7.1 | 19 | NO | NO |
CVE-2023-32470MEDIUM
Dell Digital Delivery versions prior to 5.0.82.0 contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit th | Sep 8, 2023 | 5.5 | 19 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.