VYPR

CWE-426

Untrusted Search Path

BaseStableLikelihood: High

Description

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-38

CVEs mapped to this weakness (691)

page 14 of 35
  • CVE-2018-5003HigAug 29, 2018
    risk 0.51cvss 7.8epss 0.05

    Adobe Creative Cloud Desktop Application before 4.5.5.342 (installer) has an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.

  • CVE-2018-0621HigJul 26, 2018
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in LOGICOOL CONNECTION UTILITY SOFTWARE versions before 2.30.9 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2018-0620HigJul 26, 2018
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in LOGICOOL Game Software versions before 8.87.116 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2018-0619HigJul 26, 2018
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in the installer of Glarysoft Glary Utilities (Glary Utilities 5.99 and earlier and Glary Utilities Pro 5.99 and earlier) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2018-13133HigJul 4, 2018
    risk 0.51cvss 7.8epss 0.00

    Golden Frog VyprVPN before 2018-06-21 has a vulnerability associated with the installation process on Windows.

  • CVE-2018-13102HigJul 3, 2018
    risk 0.51cvss 7.8epss 0.01

    AnyDesk before "12.06.2018 - 4.1.3" on Windows 7 SP1 has a DLL preloading vulnerability.

  • CVE-2018-0609HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in LINE for Windows versions before 5.8.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2018-0601HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in axpdfium v0.01 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2018-0600HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in the installer of PlayMemories Home for Windows ver.5.5.01 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2018-0599HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.05

    Untrusted search path vulnerability in the installer of Visual C++ Redistributable allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2018-0598HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.10

    Untrusted search path vulnerability in Self-extracting archive files created by IExpress bundled with Microsoft Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2018-0597HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.05

    Untrusted search path vulnerability in the installer of Visual Studio Code allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2018-0596HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.05

    Untrusted search path vulnerability in the installer of Visual Studio Community allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2018-0595HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.05

    Untrusted search path vulnerability in the installer of Skype for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2018-0594HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.05

    Untrusted search path vulnerability in Skype for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2018-0593HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.05

    Untrusted search path vulnerability in the installer of Microsoft OneDrive allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2018-0592HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.05

    Untrusted search path vulnerability in Microsoft OneDrive allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2018-0563HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in the installer of FLET'S VIRUS CLEAR Easy Setup & Application Tool ver.13.0 and earlier versions and FLET'S VIRUS CLEAR v6 Easy Setup & Application Tool ver.13.0 and earlier versions allows an attacker to gain privileges via a Trojan horse…

  • CVE-2017-7755HigJun 11, 2018
    risk 0.51cvss 7.8epss 0.01

    The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run. This allows privileged execution if the installer is run with elevated privileges. Note: This attack only affects Windows operating systems.…

  • CVE-2018-6514HigJun 11, 2018
    risk 0.51cvss 7.8epss 0.01

    In Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, Puppet Agent 5.5.x prior to 5.5.2, Facter on Windows is vulnerable to a DLL preloading attack, which could lead to a privilege escalation.