VYPR

CWE-426

Untrusted Search Path

BaseStableLikelihood: High

Description

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-38

CVEs mapped to this weakness (672)

page 28 of 34
  • CVE-2022-0014MedJan 12, 2022
    risk 0.44cvss 6.7epss 0.00

    An untrusted search path vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker with file creation privilege in the Windows root directory (such as C:\) to store a program that can then be unintentionally executed by another local user when…

  • CVE-2019-6196MedJun 9, 2020
    risk 0.44cvss 6.7epss 0.00

    A symbolic link vulnerability in some Lenovo installation packages, prior to version 1.2.9.3, could allow privileged file operations during file extraction and installation.

  • CVE-2019-6173MedJun 9, 2020
    risk 0.44cvss 6.7epss 0.00

    A DLL search path vulnerability could allow privilege escalation in some Lenovo installation packages, prior to version 1.2.9.3, during installation if an attacker already has administrative privileges.

  • CVE-2019-18196MedOct 24, 2019
    risk 0.44cvss 6.7epss 0.01

    A DLL side loading vulnerability in the Windows Service in TeamViewer versions up to 11.0.133222 (fixed in 11.0.214397), 12.0.181268 (fixed in 12.0.214399), 13.2.36215 (fixed in 13.2.36216), and 14.6.4835 (fixed in 14.7.1965) on Windows could allow an attacker to perform code…

  • CVE-2019-17449MedOct 10, 2019
    risk 0.44cvss 6.7epss 0.00

    Avira Software Updater before 2.0.6.21094 allows a DLL side-loading attack. NOTE: The vendor thinks that this vulnerability is invalid because exploiting it would require at least administrator privileges and would gain only SYSTEM privileges

  • CVE-2018-10875HigJul 13, 2018
    risk 0.44cvss 7.8epss 0.01

    A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.

  • CVE-2018-10874HigJul 2, 2018
    risk 0.44cvss 7.8epss 0.00

    In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.

  • CVE-2018-1000201HigJun 22, 2018
    risk 0.44cvss 7.8epss 0.01

    ruby-ffi version 1.9.23 and earlier has a DLL loading issue which can be hijacked on Windows OS, when a Symbol is used as DLL name instead of a String This vulnerability appears to have been fixed in v1.9.24 and later.

  • CVE-2017-12313MedNov 16, 2017
    risk 0.44cvss 6.7epss 0.01

    An untrusted search path (aka DLL Preload) vulnerability in the Cisco Network Academy Packet Tracer software could allow an authenticated, local attacker to execute arbitrary code via DLL hijacking if a local user with administrative privileges executes the installer in the…

  • CVE-2017-12312MedNov 16, 2017
    risk 0.44cvss 6.7epss 0.01

    An untrusted search path (aka DLL Preloading) vulnerability in the Cisco Immunet antimalware installer could allow an authenticated, local attacker to execute arbitrary code via DLL hijacking if a local user with administrative privileges executes the installer in the current…

  • CVE-2015-3887HigSep 21, 2017
    risk 0.44cvss 7.8epss 0.00

    Untrusted search path vulnerability in ProxyChains-NG before 4.9 allows local users to gain privileges via a Trojan horse libproxychains4.so library in the current working directory, which is referenced in the LD_PRELOAD path.

  • CVE-2016-1202HigApr 25, 2016
    risk 0.44cvss 7.8epss 0.00

    Untrusted search path vulnerability in Atom Electron before 0.33.5 allows local users to gain privileges via a Trojan horse Node.js module in a parent directory of a directory named on a require line.

  • CVE-2021-4435HigFeb 4, 2024
    risk 0.43cvss 7.7epss 0.00

    An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be executed in unexpected ways.

  • CVE-2026-42830MedMay 12, 2026
    risk 0.42cvss 6.5epss 0.00

    Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

  • CVE-2026-25792MedMar 20, 2026
    risk 0.42cvss 6.5epss 0.00

    Greenshot is an open source Windows screenshot utility. Versions 1.3.312 and below have untrusted executable search path / binary hijacking vulnerability that allows a local attacker to execute arbitrary code when the affected Windows application launches explorer.exe without…

  • CVE-2026-25992HigFeb 10, 2026
    risk 0.42cvss 7.5epss 0.01

    SiYuan is a personal knowledge management system. Prior to 3.5.5, the /api/file/getFile endpoint uses case-sensitive string equality checks to block access to sensitive files. On case-insensitive file systems such as Windows, attackers can bypass restrictions using mixed-case…

  • CVE-2019-25257MedDec 24, 2025
    risk 0.42cvss 6.5epss 0.00

    LogicalDOC Enterprise 7.7.4 contains multiple authenticated OS command execution vulnerabilities that allow attackers to manipulate binary paths when changing system settings. Attackers can exploit these vulnerabilities by modifying configuration parameters like…

  • CVE-2024-42439MedAug 14, 2024
    risk 0.42cvss 6.5epss 0.00

    Untrusted search path in the installer for Zoom Workplace Desktop App for macOS and Zoom Meeting SDK for macOS before 6.1.0 may allow a privileged user to conduct an escalation of privilege via local access.

  • CVE-2023-26031HigNov 16, 2023
    risk 0.42cvss 7.5epss 0.02

    Relative library resolution in linux container-executor binary in Apache Hadoop 3.3.1-3.3.4 on Linux allows local user to gain root privileges. If the YARN cluster is accepting work from remote (authenticated) users, this MAY permit remote users to gain root privileges. Hadoop…

  • CVE-2022-29970HigMay 2, 2022
    risk 0.42cvss 7.5epss 0.02

    Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.