VYPR

CWE-426

Untrusted Search Path

BaseStableLikelihood: High

Description

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-38

CVEs mapped to this weakness (672)

page 5 of 34
  • CVE-2026-35368HigApr 22, 2026
    risk 0.51cvss 7.8epss 0.00

    A vulnerability exists in the chroot utility of uutils coreutils when using the --userspec option. The utility resolves the user specification via getpwnam() after entering the chroot but before dropping root privileges. On glibc-based systems, this can trigger the Name Service…

  • CVE-2026-33156HigMar 20, 2026
    risk 0.51cvss 7.8epss 0.00

    ScreenToGif is a screen recording tool. In versions from 2.42.1 and prior, ScreenToGif is vulnerable to DLL sideloading via version.dll . When the portable executable is run from a user-writable directory, it loads version.dll from the application directory instead of the…

  • CVE-2026-25190HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally.

  • CVE-2026-2998HigFeb 23, 2026
    risk 0.51cvss 7.8epss 0.00

    ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a crafted DLL file in the same directory as the program, thereby executing arbitrary code.

  • CVE-2026-25880HigFeb 9, 2026
    risk 0.51cvss 7.8epss 0.00

    SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, the PDF reader allows execution of a malicious binary (explorer.exe) located in the same directory as the opened PDF when the user clicks File → “Show in folder”. This behavior leads to arbitrary code…

  • CVE-2026-0662HigFeb 4, 2026
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current process due to an Untrusted Search Path being utilized.

  • CVE-2025-12793HigJan 6, 2026
    risk 0.51cvss 7.8epss 0.00

    An uncontrolled DLL loading path vulnerability exists in AsusSoftwareManagerAgent. A local attacker may influence the application to load a DLL from an attacker-controlled location, potentially resulting in arbitrary code execution. Refer to the ' Security Update for MyASUS'…

  • CVE-2025-67722HigDec 16, 2025
    risk 0.51cvss 7.8epss 0.00

    FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to versions 16.0.45 and 17.0.24 of the FreePBX framework, an authenticated local privilege escalation exists in the deprecated FreePBX startup script `amportal`. In the deprecated…

  • CVE-2025-64785HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a…

  • CVE-2025-60718HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.

  • CVE-2025-5039HigJul 24, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.

  • CVE-2025-5335HigJun 10, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the Autodesk Installer application. Exploitation of this vulnerability may lead to code execution.

  • CVE-2024-12168HigJun 2, 2025
    risk 0.51cvss 7.8epss 0.00

    Yandex Telemost for Desktop before 2.7.0 has a DLL Hijacking Vulnerability because an untrusted search path is used.

  • CVE-2025-2501HigMay 30, 2025
    risk 0.51cvss 7.8epss 0.00

    An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.

  • CVE-2025-4802HigMay 16, 2025
    risk 0.51cvss 7.8epss 0.01

    Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or…

  • CVE-2025-27743HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path in System Center allows an authorized attacker to elevate privileges locally.

  • CVE-2025-27167HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute their own programs, access unauthorized data files, or modify configuration in unexpected ways. If the application uses a search path to…

  • CVE-2025-0707HigJan 24, 2025
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in Rise Group Rise Mode Temp CPU 2.1. It has been classified as critical. This affects an unknown part in the library CRYPTBASE.dll of the component Startup. The manipulation leads to untrusted search path. The attack needs to be approached locally.

  • CVE-2020-8094HigJan 15, 2025
    risk 0.51cvss 7.8epss 0.00

    An untrusted search path vulnerability in testinitsigs.exe as used in Bitdefender Antivirus Free 2020 allows a low-privilege attacker to execute code as SYSTEM via a specially crafted DLL file.

  • CVE-2025-21365HigJan 14, 2025
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Remote Code Execution Vulnerability