CWE-426
Untrusted Search Path
Description
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-38
CVEs mapped to this weakness (691)
page 5 of 35| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-75768 | Hig | 0.51 | 7.8 | 0.00 | Aug 25, 2026 | Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user… | ||
| CVE-2026-16869 | Hig | 0.51 | 7.8 | 0.00 | Aug 19, 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improperly scrubbed environment variables. | ||
| CVE-2026-0299 | Hig | 0.51 | 7.8 | 0.00 | Aug 13, 2026 | Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with… | ||
| CVE-2026-56174 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-41447 | Hig | 0.51 | 7.8 | 0.00 | Aug 3, 2026 | FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in the unvalidated C:\Program Files (x86)\Common Files\SSL\ directory path. Attackers can write a malicious… | ||
| CVE-2026-48346 | Hig | 0.51 | 7.9 | 0.00 | Jul 14, 2026 | Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. | ||
| CVE-2026-48565 | Hig | 0.51 | 7.8 | 0.00 | Jun 9, 2026 | Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-24064 | Hig | 0.51 | 7.8 | 0.00 | Jun 9, 2026 | Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability. A trusted XPC client component included with the product is signed with hardened runtime entitlements that permit dynamic library injection. A local attacker can set the… | ||
| CVE-2026-30906 | Hig | 0.51 | 7.8 | 0.00 | May 13, 2026 | Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access. | ||
| CVE-2026-0251 | Hig | 0.51 | 7.8 | 0.00 | May 13, 2026 | Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands… | ||
| CVE-2026-35368 | Hig | 0.51 | 7.8 | 0.00 | Apr 22, 2026 | A vulnerability exists in the chroot utility of uutils coreutils when using the --userspec option. The utility resolves the user specification via getpwnam() after entering the chroot but before dropping root privileges. On glibc-based systems, this can trigger the Name Service… | ||
| CVE-2026-33156 | Hig | 0.51 | 7.8 | 0.00 | Mar 20, 2026 | ScreenToGif is a screen recording tool. In versions from 2.42.1 and prior, ScreenToGif is vulnerable to DLL sideloading via version.dll . When the portable executable is run from a user-writable directory, it loads version.dll from the application directory instead of the… | ||
| CVE-2026-25190 | Hig | 0.51 | 7.8 | 0.01 | Mar 10, 2026 | Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-2998 | Hig | 0.51 | 7.8 | 0.00 | Feb 23, 2026 | ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a crafted DLL file in the same directory as the program, thereby executing arbitrary code. | ||
| CVE-2026-25880 | Hig | 0.51 | 7.8 | 0.00 | Feb 9, 2026 | SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, the PDF reader allows execution of a malicious binary (explorer.exe) located in the same directory as the opened PDF when the user clicks File → “Show in folder”. This behavior leads to arbitrary code… | ||
| CVE-2026-0662 | Hig | 0.51 | 7.8 | 0.00 | Feb 4, 2026 | A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current process due to an Untrusted Search Path being utilized. | ||
| CVE-2025-12793 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2026 | An uncontrolled DLL loading path vulnerability exists in AsusSoftwareManagerAgent. A local attacker may influence the application to load a DLL from an attacker-controlled location, potentially resulting in arbitrary code execution. Refer to the ' Security Update for MyASUS'… | ||
| CVE-2025-67722 | Hig | 0.51 | 7.8 | 0.00 | Dec 16, 2025 | FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to versions 16.0.45 and 17.0.24 of the FreePBX framework, an authenticated local privilege escalation exists in the deprecated FreePBX startup script `amportal`. In the deprecated… | ||
| CVE-2025-64785 | Hig | 0.51 | 7.8 | 0.00 | Dec 9, 2025 | Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a… | ||
| CVE-2025-60718 | Hig | 0.51 | 7.8 | 0.00 | Nov 11, 2025 | Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally. |
- risk 0.51cvss 7.8epss 0.00
Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user…
- risk 0.51cvss 7.8epss 0.00
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improperly scrubbed environment variables.
- risk 0.51cvss 7.8epss 0.00
Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with…
- risk 0.51cvss 7.8epss 0.00
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in the unvalidated C:\Program Files (x86)\Common Files\SSL\ directory path. Attackers can write a malicious…
- risk 0.51cvss 7.9epss 0.00
Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
- risk 0.51cvss 7.8epss 0.00
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability. A trusted XPC client component included with the product is signed with hardened runtime entitlements that permit dynamic library injection. A local attacker can set the…
- risk 0.51cvss 7.8epss 0.00
Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access.
- risk 0.51cvss 7.8epss 0.00
Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands…
- risk 0.51cvss 7.8epss 0.00
A vulnerability exists in the chroot utility of uutils coreutils when using the --userspec option. The utility resolves the user specification via getpwnam() after entering the chroot but before dropping root privileges. On glibc-based systems, this can trigger the Name Service…
- risk 0.51cvss 7.8epss 0.00
ScreenToGif is a screen recording tool. In versions from 2.42.1 and prior, ScreenToGif is vulnerable to DLL sideloading via version.dll . When the portable executable is run from a user-writable directory, it loads version.dll from the application directory instead of the…
- risk 0.51cvss 7.8epss 0.01
Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a crafted DLL file in the same directory as the program, thereby executing arbitrary code.
- risk 0.51cvss 7.8epss 0.00
SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, the PDF reader allows execution of a malicious binary (explorer.exe) located in the same directory as the opened PDF when the user clicks File → “Show in folder”. This behavior leads to arbitrary code…
- risk 0.51cvss 7.8epss 0.00
A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current process due to an Untrusted Search Path being utilized.
- risk 0.51cvss 7.8epss 0.00
An uncontrolled DLL loading path vulnerability exists in AsusSoftwareManagerAgent. A local attacker may influence the application to load a DLL from an attacker-controlled location, potentially resulting in arbitrary code execution. Refer to the ' Security Update for MyASUS'…
- risk 0.51cvss 7.8epss 0.00
FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to versions 16.0.45 and 17.0.24 of the FreePBX framework, an authenticated local privilege escalation exists in the deprecated FreePBX startup script `amportal`. In the deprecated…
- risk 0.51cvss 7.8epss 0.00
Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a…
- risk 0.51cvss 7.8epss 0.00
Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.