CWE-426
Untrusted Search Path
Description
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-38
CVEs mapped to this weakness (691)
page 11 of 35| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-12580 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2020 | An issue was discovered in IDM UltraEdit through 24.10.0.32. To exploit the vulnerability, on unpatched Windows systems, an attacker could include in the same directory as the affected executable a DLL using the name of a Windows DLL. This DLL must be preloaded by the executable… | ||
| CVE-2019-20456 | Hig | 0.51 | 7.8 | 0.01 | Feb 16, 2020 | Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Command Injection and Local Privilege Escalation via DLL hijacking. | ||
| CVE-2014-3860 | Hig | 0.51 | 7.8 | 0.01 | Feb 12, 2020 | Xilisoft Video Converter Ultimate 7.8.1 build-20140505 has a DLL Hijacking vulnerability | ||
| CVE-2013-3494 | Hig | 0.51 | 7.8 | 0.02 | Feb 12, 2020 | A Code Execution Vulnerability exists in UMPlayer 0.98 in wintab32.dll due to insufficient path restrictions when loading external libraries. which could let a malicious user execute arbitrary code. | ||
| CVE-2013-3942 | Hig | 0.51 | 7.8 | 0.01 | Feb 11, 2020 | Potplayer prior to 1.5.39659: DLL Loading Arbitrary Code Execution Vulnerability | ||
| CVE-2019-20358 | Hig | 0.51 | 7.8 | 0.05 | Jan 30, 2020 | Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed. Another attack vector similar to… | ||
| CVE-2013-2773 | Hig | 0.51 | 7.8 | 0.00 | Jan 14, 2020 | Nitro PDF 8.5.0.26: A specially crafted DLL file can facilitate Arbitrary Code Execution | ||
| CVE-2016-6593 | Hig | 0.51 | 7.8 | 0.01 | Jan 8, 2020 | A code-execution vulnerability exists during startup in jhi.dll and otpiha.dll in Symantec VIP Access Desktop before 2.2.2, which could let local malicious users execute arbitrary code. | ||
| CVE-2019-6019 | Hig | 0.51 | 7.8 | 0.01 | Dec 26, 2019 | Untrusted search path vulnerability in STAMP Workbench installer all versions allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | ||
| CVE-2019-19929 | Hig | 0.51 | 7.8 | 0.01 | Dec 23, 2019 | An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner before 8.0.1 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded by the product. | ||
| CVE-2019-8801 | Hig | 0.51 | 7.8 | 0.00 | Dec 18, 2019 | A dynamic library loading issue existed in iTunes setup. This was addressed with improved path searching. This issue is fixed in macOS Catalina 10.15.1, iTunes for Windows 12.10.2. Running the iTunes installer in an untrusted directory may result in arbitrary code execution. | ||
| CVE-2019-14599 | Hig | 0.51 | 7.8 | 0.00 | Dec 16, 2019 | Unquoted service path in Control Center-I version 2.1.0.0 and earlier may allow an authenticated user to potentially enable escalation of privilege via local access. | ||
| CVE-2019-4606 | Hig | 0.51 | 7.8 | 0.00 | Dec 12, 2019 | IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 could allow a local attacker to execute arbitrary code on the system, caused by an untrusted search path vulnerability. By using a executable file, an attacker could exploit this vulnerability to execute arbitrary code on… | ||
| CVE-2019-15628 | Hig | 0.51 | 7.8 | 0.01 | Dec 2, 2019 | Trend Micro Security (Consumer) 2020 (v16.0.1221 and below) is affected by a DLL hijacking vulnerability that could allow an attacker to use a specific service as an execution and/or persistence mechanism which could execute a malicious program each time the service is started. | ||
| CVE-2019-17446 | Hig | 0.51 | 7.8 | 0.00 | Nov 22, 2019 | An issue was discovered in Eracent EPA Agent through 10.2.26. The agent executable, when installed for non-root operations (scanning), can be used to start external programs with elevated permissions because of an Untrusted Search Path. | ||
| CVE-2019-6189 | Hig | 0.51 | 7.8 | 0.00 | Nov 20, 2019 | A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an administrative user to load an unsigned DLL. | ||
| CVE-2019-17664 | Hig | 0.51 | 7.8 | 0.00 | Oct 16, 2019 | NSA Ghidra through 9.0.4 uses a potentially untrusted search path. When executing Ghidra from a given path, the Java process working directory is set to this path. Then, when launching the Python interpreter via the "Ghidra Codebrowser > Window > Python" option, Ghidra will try… | ||
| CVE-2019-14960 | Hig | 0.51 | 7.8 | 0.00 | Oct 1, 2019 | JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file. | ||
| CVE-2019-13357 | Hig | 0.51 | 7.8 | 0.01 | Sep 24, 2019 | In Total Defense Anti-virus 9.0.0.773, resource acquisition from the untrusted search path C:\ used by caschelp.exe allows local attackers to hijack ccGUIFrm.dll, which leads to code execution. SYSTEM-level code execution can be achieved when the ccSchedulerSVC service runs the… | ||
| CVE-2019-6826 | Hig | 0.51 | 7.8 | 0.01 | Sep 17, 2019 | A CWE-426: Untrusted Search Path vulnerability exists in SoMachine HVAC v2.4.1 and earlier versions, which could cause arbitrary code execution on the system running SoMachine HVAC when a malicious DLL library is loaded by the product. |
- risk 0.51cvss 7.8epss 0.00
An issue was discovered in IDM UltraEdit through 24.10.0.32. To exploit the vulnerability, on unpatched Windows systems, an attacker could include in the same directory as the affected executable a DLL using the name of a Windows DLL. This DLL must be preloaded by the executable…
- risk 0.51cvss 7.8epss 0.01
Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Command Injection and Local Privilege Escalation via DLL hijacking.
- risk 0.51cvss 7.8epss 0.01
Xilisoft Video Converter Ultimate 7.8.1 build-20140505 has a DLL Hijacking vulnerability
- risk 0.51cvss 7.8epss 0.02
A Code Execution Vulnerability exists in UMPlayer 0.98 in wintab32.dll due to insufficient path restrictions when loading external libraries. which could let a malicious user execute arbitrary code.
- risk 0.51cvss 7.8epss 0.01
Potplayer prior to 1.5.39659: DLL Loading Arbitrary Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.05
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed. Another attack vector similar to…
- risk 0.51cvss 7.8epss 0.00
Nitro PDF 8.5.0.26: A specially crafted DLL file can facilitate Arbitrary Code Execution
- risk 0.51cvss 7.8epss 0.01
A code-execution vulnerability exists during startup in jhi.dll and otpiha.dll in Symantec VIP Access Desktop before 2.2.2, which could let local malicious users execute arbitrary code.
- risk 0.51cvss 7.8epss 0.01
Untrusted search path vulnerability in STAMP Workbench installer all versions allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
- risk 0.51cvss 7.8epss 0.01
An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner before 8.0.1 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded by the product.
- risk 0.51cvss 7.8epss 0.00
A dynamic library loading issue existed in iTunes setup. This was addressed with improved path searching. This issue is fixed in macOS Catalina 10.15.1, iTunes for Windows 12.10.2. Running the iTunes installer in an untrusted directory may result in arbitrary code execution.
- risk 0.51cvss 7.8epss 0.00
Unquoted service path in Control Center-I version 2.1.0.0 and earlier may allow an authenticated user to potentially enable escalation of privilege via local access.
- risk 0.51cvss 7.8epss 0.00
IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 could allow a local attacker to execute arbitrary code on the system, caused by an untrusted search path vulnerability. By using a executable file, an attacker could exploit this vulnerability to execute arbitrary code on…
- risk 0.51cvss 7.8epss 0.01
Trend Micro Security (Consumer) 2020 (v16.0.1221 and below) is affected by a DLL hijacking vulnerability that could allow an attacker to use a specific service as an execution and/or persistence mechanism which could execute a malicious program each time the service is started.
- risk 0.51cvss 7.8epss 0.00
An issue was discovered in Eracent EPA Agent through 10.2.26. The agent executable, when installed for non-root operations (scanning), can be used to start external programs with elevated permissions because of an Untrusted Search Path.
- risk 0.51cvss 7.8epss 0.00
A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an administrative user to load an unsigned DLL.
- risk 0.51cvss 7.8epss 0.00
NSA Ghidra through 9.0.4 uses a potentially untrusted search path. When executing Ghidra from a given path, the Java process working directory is set to this path. Then, when launching the Python interpreter via the "Ghidra Codebrowser > Window > Python" option, Ghidra will try…
- risk 0.51cvss 7.8epss 0.00
JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file.
- risk 0.51cvss 7.8epss 0.01
In Total Defense Anti-virus 9.0.0.773, resource acquisition from the untrusted search path C:\ used by caschelp.exe allows local attackers to hijack ccGUIFrm.dll, which leads to code execution. SYSTEM-level code execution can be achieved when the ccSchedulerSVC service runs the…
- risk 0.51cvss 7.8epss 0.01
A CWE-426: Untrusted Search Path vulnerability exists in SoMachine HVAC v2.4.1 and earlier versions, which could cause arbitrary code execution on the system running SoMachine HVAC when a malicious DLL library is loaded by the product.