VYPR

CWE-426

Untrusted Search Path

BaseStableLikelihood: High

Description

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-38

CVEs mapped to this weakness (691)

page 25 of 35
  • CVE-2023-36780HigOct 10, 2023
    risk 0.47cvss 7.2epss 0.03

    Skype for Business Remote Code Execution Vulnerability

  • CVE-2023-39201HigSep 12, 2023
    risk 0.47cvss 7.2epss 0.00

    Untrusted search path in CleanZoom before file date 07/24/2023 may allow a privileged user to conduct an escalation of privilege via local access.

  • CVE-2023-36540HigAug 8, 2023
    risk 0.47cvss 7.3epss 0.00

    Untrusted search path in the installer for Zoom Desktop Client for Windows before 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.

  • CVE-2023-22743HigFeb 14, 2023
    risk 0.47cvss 7.2epss 0.00

    Git for Windows is the Windows port of the revision control system Git. Prior to Git for Windows version 2.39.2, by carefully crafting DLL and putting into a subdirectory of a specific name living next to the Git for Windows installer, Windows can be tricked into side-loading…

  • CVE-2020-10733HigSep 16, 2020
    risk 0.47cvss 7.3epss 0.01

    The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having…

  • CVE-2020-0570HigSep 14, 2020
    risk 0.47cvss 7.3epss 0.01

    Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.

  • CVE-2020-14350HigAug 24, 2020
    risk 0.47cvss 7.3epss 0.01

    It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the installation or update of such…

  • CVE-2020-8317HigJul 24, 2020
    risk 0.47cvss 7.3epss 0.00

    A DLL search path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges.

  • CVE-2019-19161HigJun 30, 2020
    risk 0.47cvss 7.2epss 0.01

    CyMiInstaller322 ActiveX which runs MIPLATFORM downloads files required to run applications. A vulnerability in downloading files by CyMiInstaller322 ActiveX caused by an attacker to download randomly generated DLL files and MIPLATFORM to load those DLLs due to insufficient…

  • CVE-2020-7260HigMar 26, 2020
    risk 0.47cvss 7.3epss 0.00

    DLL Side Loading vulnerability in the installer for McAfee Application and Change Control (MACC) prior to 8.3 allows local users to execute arbitrary code via execution from a compromised folder.

  • CVE-2019-16861HigNov 19, 2019
    risk 0.47cvss 7.3epss 0.00

    Code42 server through 7.0.2 for Windows has an Untrusted Search Path. In certain situations, a non-administrative attacker on the local server could create or modify a dynamic-link library (DLL). The Code42 service could then load it at runtime, and potentially execute arbitrary…

  • CVE-2019-16860HigNov 19, 2019
    risk 0.47cvss 7.3epss 0.00

    Code42 app through version 7.0.2 for Windows has an Untrusted Search Path. In certain situations, a non-administrative attacker on the local machine could create or modify a dynamic-link library (DLL). The Code42 service could then load it at runtime, and potentially execute…

  • CVE-2019-3745HigOct 7, 2019
    risk 0.47cvss 7.3epss 0.00

    The vulnerability is limited to the installers of Dell Encryption Enterprise versions prior to 10.4.0 and Dell Endpoint Security Suite Enterprise versions prior to 2.4.0. This issue is exploitable only during the installation of the product by an administrator. A local…

  • CVE-2019-3587HigJan 23, 2019
    risk 0.47cvss 7.2epss 0.01

    DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0.18 allows local users to execute arbitrary code via execution from a compromised folder.

  • CVE-2017-2157HigMay 12, 2017
    risk 0.47cvss 7.3epss 0.01

    Untrusted search path vulnerability in installers for The Public Certification Service for Individuals "The JPKI user's software (for Windows 7 and later)" Ver3.1 and earlier, The Public Certification Service for Individuals "The JPKI user's software (for Windows Vista)", The…

  • CVE-2026-18605HigAug 3, 2026
    risk 0.46cvss 7.0epss 0.00

    A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. Affected is an unknown function in the library AppCheckD.sys of the component Kernel Mini-Filter Driver. Performing a manipulation results in uncontrolled search path. The attack requires a local approach.…

  • CVE-2026-6421HigApr 17, 2026
    risk 0.46cvss 7.0epss 0.00

    A vulnerability has been found in Mobatek MobaXterm Home Edition up to 26.1. This affects an unknown part in the library msimg32.dll. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The attack is considered to have high complexity. It…

  • CVE-2026-4962HigMar 27, 2026
    risk 0.46cvss 7.0epss 0.00

    A security flaw has been discovered in UltraVNC up to 1.6.4.0. Affected by this issue is some unknown functionality in the library version.dll of the component Service. The manipulation results in uncontrolled search path. The attack needs to be approached locally. This attack…

  • CVE-2026-4546HigMar 22, 2026
    risk 0.46cvss 7.0epss 0.00

    A weakness has been identified in Flos Freeware Notepad2 4.2.25. This impacts an unknown function in the library TextShaping.dll. Executing a manipulation can lead to uncontrolled search path. The attack is restricted to local execution. The attack requires a high level of…

  • CVE-2026-4545HigMar 22, 2026
    risk 0.46cvss 7.0epss 0.00

    A security flaw has been discovered in Flos Freeware Notepad2 4.2.25. This affects an unknown function in the library PROPSYS.dll. Performing a manipulation results in uncontrolled search path. The attack is only possible with local access. The attack is considered to have high…