CWE-1386: Insecure Operation on Windows Junction / Mount Point

low-risk

The product opens a file or directory, but it does not properly prevent the name from being associated with a junction or mount point to a destination that is outside of the intended control sphere.

Abstraction: Base

Common Consequences

Confidentiality Read Files or Directories
Integrity Modify Files or Directories
Availability Modify Files or Directories

Real-World Examples (10)

CVE CVSS EPSS KEV
CVE-2023-40623 6.2 0.2%
CVE-2022-42291 8.2 0.1%
CVE-2023-5834 3.8 0.1%
CVE-2023-28065 6.7 0.1%
CVE-2023-23698 5.5 0.1%
CVE-2024-36340 6.6 0.1%
CVE-2023-28071 6.3 0.1%
CVE-2023-23697 4.7 0.0%
CVE-2023-24572 4.7 0.0%
CVE-2023-32454 6.3 0.0%
0
/ 100
low-risk
Active Threat 0/50 · Minimal
Exploit Availability 0/50 · Minimal