CWE-426
Untrusted Search Path
Description
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-38
CVEs mapped to this weakness (691)
page 4 of 35| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-17980 | Hig | 0.54 | 7.8 | 0.05 | Oct 15, 2018 | NoMachine before 5.3.27 and 6.x before 6.3.6 allows attackers to gain privileges via a Trojan horse wintab32.dll file located in the same directory as a .nxs file, as demonstrated by a scenario where the .nxs file and the DLL are in the current working directory, and the Trojan… | ||
| CVE-2014-8358 | Hig | 0.54 | 7.8 | 0.05 | Dec 11, 2017 | Huawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014) and before V200R003B015D02SP08C1014 (23.015.02.08.1014) use a weak ACL for the "Mobile Partner" directory, which allows remote attackers to gain SYSTEM… | ||
| CVE-2017-7642 | Hig | 0.54 | 7.8 | 0.01 | Aug 2, 2017 | The sudo helper in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.21 allows local users to gain root privileges by leveraging failure to verify the path to the encoded ruby script or scrub the PATH variable. | ||
| CVE-2024-58250 | Cri | 0.53 | 9.3 | 0.00 | Apr 22, 2025 | The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges. | ||
| CVE-2024-32019 | Hig | 0.53 | 8.8 | 0.01 | Apr 12, 2024 | Netdata is an open source observability tool. In affected versions the `ndsudo` tool shipped with affected versions of the Netdata Agent allows an attacker to run arbitrary programs with root permissions. The `ndsudo` tool is packaged as a `root`-owned executable with the SUID… | ||
| CVE-2023-36536 | Hig | 0.53 | 8.2 | 0.00 | Jul 11, 2023 | Untrusted search path in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access. | ||
| CVE-2023-34119 | Hig | 0.53 | 8.2 | 0.00 | Jul 11, 2023 | Insecure temporary file in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access. | ||
| CVE-2023-26036 | Hig | 0.53 | 8.1 | 0.01 | Feb 25, 2023 | ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain a Local File Inclusion (Untrusted Search Path) vulnerability via /web/index.php. By controlling… | ||
| CVE-2022-31012 | Hig | 0.53 | 8.2 | 0.00 | Jul 12, 2022 | Git for Windows is a fork of Git that contains Windows-specific patches. This vulnerability in versions prior to 2.37.1 lets Git for Windows' installer execute a binary into `C:\mingw64\bin\git.exe` by mistake. This only happens upon a fresh install, not when upgrading Git for… | ||
| CVE-2021-31841 | Hig | 0.53 | 8.2 | 0.00 | Sep 22, 2021 | A DLL sideloading vulnerability in McAfee Agent for Windows prior to 5.7.4 could allow a local user to perform a DLL sideloading attack with an unsigned DLL with a specific name and in a specific location. This would result in the user gaining elevated permissions and the… | ||
| CVE-2026-45721 | Cri | 0.52 | 9.0 | 0.00 | May 26, 2026 | Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that resolves to a directory without an index file, DirPage walks upward through parent directories — past the configured server root — looking for a file named… | ||
| CVE-2025-31480 | Cri | 0.52 | 9.1 | 0.00 | Apr 4, 2025 | aiven-extras is a PostgreSQL extension. This is a privilege escalation vulnerability, allowing elevation to superuser inside PostgreSQL databases that use the aiven-extras package. The vulnerability leverages the format function not being schema-prefixed. Affected users should… | ||
| CVE-2024-8733 | Hig | 0.52 | 8.0 | 0.00 | Oct 2, 2024 | A potential security vulnerability has been identified in the HP One Agent for certain HP PC products, which might allow for escalation of privilege. HP is releasing software updates to mitigate this potential vulnerability. | ||
| CVE-2024-35260 | Hig | 0.52 | 8.0 | 0.01 | Jun 27, 2024 | An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network. | ||
| CVE-2023-36778 | Hig | 0.52 | 8.0 | 0.04 | Oct 10, 2023 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2020-1458 | Hig | 0.52 | 7.8 | 0.11 | Jul 14, 2020 | A remote code execution vulnerability exists when Microsoft Office improperly validates input before loading dynamic link library (DLL) files, aka 'Microsoft Office Remote Code Execution Vulnerability'. | ||
| CVE-2019-12569 | Hig | 0.52 | 7.8 | 0.15 | Jun 3, 2019 | A vulnerability in Viber before 10.7.0 for Desktop (Windows) could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI. An attacker could exploit this vulnerability by convincing a… | ||
| CVE-2019-0809 | Hig | 0.52 | 7.8 | 0.11 | Apr 9, 2019 | A remote code execution vulnerability exists when the Visual Studio C++ Redistributable Installer improperly validates input before loading dynamic link library (DLL) files, aka 'Visual Studio Remote Code Execution Vulnerability'. | ||
| CVE-2026-69785 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Untrusted search path in Windows Smart Card allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69328 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally. |
- risk 0.54cvss 7.8epss 0.05
NoMachine before 5.3.27 and 6.x before 6.3.6 allows attackers to gain privileges via a Trojan horse wintab32.dll file located in the same directory as a .nxs file, as demonstrated by a scenario where the .nxs file and the DLL are in the current working directory, and the Trojan…
- risk 0.54cvss 7.8epss 0.05
Huawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014) and before V200R003B015D02SP08C1014 (23.015.02.08.1014) use a weak ACL for the "Mobile Partner" directory, which allows remote attackers to gain SYSTEM…
- risk 0.54cvss 7.8epss 0.01
The sudo helper in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.21 allows local users to gain root privileges by leveraging failure to verify the path to the encoded ruby script or scrub the PATH variable.
- risk 0.53cvss 9.3epss 0.00
The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges.
- risk 0.53cvss 8.8epss 0.01
Netdata is an open source observability tool. In affected versions the `ndsudo` tool shipped with affected versions of the Netdata Agent allows an attacker to run arbitrary programs with root permissions. The `ndsudo` tool is packaged as a `root`-owned executable with the SUID…
- risk 0.53cvss 8.2epss 0.00
Untrusted search path in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.
- risk 0.53cvss 8.2epss 0.00
Insecure temporary file in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.
- risk 0.53cvss 8.1epss 0.01
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain a Local File Inclusion (Untrusted Search Path) vulnerability via /web/index.php. By controlling…
- risk 0.53cvss 8.2epss 0.00
Git for Windows is a fork of Git that contains Windows-specific patches. This vulnerability in versions prior to 2.37.1 lets Git for Windows' installer execute a binary into `C:\mingw64\bin\git.exe` by mistake. This only happens upon a fresh install, not when upgrading Git for…
- risk 0.53cvss 8.2epss 0.00
A DLL sideloading vulnerability in McAfee Agent for Windows prior to 5.7.4 could allow a local user to perform a DLL sideloading attack with an unsigned DLL with a specific name and in a specific location. This would result in the user gaining elevated permissions and the…
- risk 0.52cvss 9.0epss 0.00
Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that resolves to a directory without an index file, DirPage walks upward through parent directories — past the configured server root — looking for a file named…
- risk 0.52cvss 9.1epss 0.00
aiven-extras is a PostgreSQL extension. This is a privilege escalation vulnerability, allowing elevation to superuser inside PostgreSQL databases that use the aiven-extras package. The vulnerability leverages the format function not being schema-prefixed. Affected users should…
- risk 0.52cvss 8.0epss 0.00
A potential security vulnerability has been identified in the HP One Agent for certain HP PC products, which might allow for escalation of privilege. HP is releasing software updates to mitigate this potential vulnerability.
- risk 0.52cvss 8.0epss 0.01
An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.
- risk 0.52cvss 8.0epss 0.04
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.52cvss 7.8epss 0.11
A remote code execution vulnerability exists when Microsoft Office improperly validates input before loading dynamic link library (DLL) files, aka 'Microsoft Office Remote Code Execution Vulnerability'.
- risk 0.52cvss 7.8epss 0.15
A vulnerability in Viber before 10.7.0 for Desktop (Windows) could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI. An attacker could exploit this vulnerability by convincing a…
- risk 0.52cvss 7.8epss 0.11
A remote code execution vulnerability exists when the Visual Studio C++ Redistributable Installer improperly validates input before loading dynamic link library (DLL) files, aka 'Visual Studio Remote Code Execution Vulnerability'.
- risk 0.51cvss 7.8epss 0.00
Untrusted search path in Windows Smart Card allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.