VYPR

CWE-426

Untrusted Search Path

BaseStableLikelihood: High

Description

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-38

CVEs mapped to this weakness (691)

page 12 of 35
  • CVE-2019-8461HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.01

    Check Point Endpoint Security Initial Client for Windows before version E81.30 tries to load a DLL placed in any PATH location on a clean image without Endpoint Client installed. An attacker can leverage this to gain LPE using a specially crafted DLL placed in any PATH location…

  • CVE-2019-15295HigAug 21, 2019
    risk 0.51cvss 7.8epss 0.01

    An Untrusted Search Path vulnerability in the ServiceInstance.dll library versions 1.0.15.119 and lower, as used in Bitdefender Antivirus Free 2020 versions prior to 1.0.15.138, allows an attacker to load an arbitrary DLL file from the search path.

  • CVE-2019-6165HigAug 19, 2019
    risk 0.51cvss 7.8epss 0.00

    A DLL search path vulnerability was reported in PaperDisplay Hotkey Service version 1.2.0.8 that could allow privilege escalation. Lenovo has ended support for PaperDisplay Hotkey software as the Night light feature introduced in Windows 10 Build 1703 provides similar features.

  • CVE-2019-5631HigAug 19, 2019
    risk 0.51cvss 7.8epss 0.01

    The Rapid7 InsightAppSec broker suffers from a DLL injection vulnerability in the 'prunsrv.exe' component of the product. If exploited, a local user of the system (who must already be authenticated to the operating system) can elevate their privileges with this vulnerability to…

  • CVE-2019-9492HigJul 26, 2019
    risk 0.51cvss 7.8epss 0.01

    A DLL side-loading vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow an authenticated attacker to gain code execution and terminate the product's process - disabling endpoint protection. The attacker must have already gained authentication and have local access…

  • CVE-2019-1010100HigJul 19, 2019
    risk 0.51cvss 7.8epss 0.01

    Akeo Consulting Rufus 3.0 and earlier is affected by: DLL search order hijacking. The impact is: Arbitrary code execution WITH escalation of privilege. The component is: Executable installers, portable executables (ALL executables on the web site). The attack vector is:…

  • CVE-2019-12576HigJul 11, 2019
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The openvpn_launcher binary is setuid root. This program is called during the connection…

  • CVE-2019-12574HigJul 11, 2019
    risk 0.51cvss 7.8epss 0.02

    A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v1.0 for Windows could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The PIA client is vulnerable to a DLL injection vulnerability during the software…

  • CVE-2019-10971HigJun 12, 2019
    risk 0.51cvss 7.8epss 0.01

    The application (Network Configurator for DeviceNet Safety 3.41 and prior) searches for resources by means of an untrusted search path that could execute a malicious .dll file not under the application's direct control and outside the intended directories.

  • CVE-2019-5589HigMay 28, 2019
    risk 0.51cvss 7.8epss 0.03

    An Unsafe Search Path vulnerability in FortiClient Online Installer (Windows version before 6.0.6) may allow an unauthenticated, remote attacker with control over the directory in which FortiClientOnlineInstaller.exe resides to execute arbitrary code on the system via uploading…

  • CVE-2019-5958HigMay 17, 2019
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in Electronic reception and examination of application for radio licenses Offline 1.0.9.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2019-5957HigMay 17, 2019
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in Installer of Electronic reception and examination of application for radio licenses Online 1.0.9.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2019-5429HigApr 29, 2019
    risk 0.51cvss 7.8epss 0.03

    Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's home directory.

  • CVE-2018-18367HigApr 25, 2019
    risk 0.51cvss 7.8epss 0.02

    Symantec Endpoint Protection Manager (SEPM) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a…

  • CVE-2018-18369HigApr 25, 2019
    risk 0.51cvss 7.8epss 0.02

    Norton Security (Windows client) prior to 22.16.3 and SEP SBE (Windows client) prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22 & SEP-12.1.7484.7002, may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call…

  • CVE-2018-18913HigMar 21, 2019
    risk 0.51cvss 7.8epss 0.00

    Opera before 57.0.3098.106 is vulnerable to a DLL Search Order hijacking attack where an attacker can send a ZIP archive composed of an HTML page along with a malicious DLL to the target. Once the document is opened, it may allow the attacker to take full control of the system…

  • CVE-2019-6724HigMar 21, 2019
    risk 0.51cvss 7.8epss 0.01

    The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process and can allow an unprivileged local attacker to load a malicious library, resulting in arbitrary code executing as root.

  • CVE-2019-5922HigMar 12, 2019
    risk 0.51cvss 7.8epss 0.05

    Untrusted search path vulnerability in The installer of Microsoft Teams allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2019-5921HigMar 12, 2019
    risk 0.51cvss 7.8epss 0.05

    Untrusted search path vulnerability in Windows 7 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2019-5913HigFeb 13, 2019
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in the installer of LHMelting (LHMelting for Win32 Ver 1.65.3.6 and earlier) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.