CWE-426
Untrusted Search Path
Description
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-38
CVEs mapped to this weakness (672)
page 5 of 34| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-35368 | Hig | 0.51 | 7.8 | 0.00 | Apr 22, 2026 | A vulnerability exists in the chroot utility of uutils coreutils when using the --userspec option. The utility resolves the user specification via getpwnam() after entering the chroot but before dropping root privileges. On glibc-based systems, this can trigger the Name Service… | ||
| CVE-2026-33156 | Hig | 0.51 | 7.8 | 0.00 | Mar 20, 2026 | ScreenToGif is a screen recording tool. In versions from 2.42.1 and prior, ScreenToGif is vulnerable to DLL sideloading via version.dll . When the portable executable is run from a user-writable directory, it loads version.dll from the application directory instead of the… | ||
| CVE-2026-25190 | Hig | 0.51 | 7.8 | 0.01 | Mar 10, 2026 | Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-2998 | Hig | 0.51 | 7.8 | 0.00 | Feb 23, 2026 | ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a crafted DLL file in the same directory as the program, thereby executing arbitrary code. | ||
| CVE-2026-25880 | Hig | 0.51 | 7.8 | 0.00 | Feb 9, 2026 | SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, the PDF reader allows execution of a malicious binary (explorer.exe) located in the same directory as the opened PDF when the user clicks File → “Show in folder”. This behavior leads to arbitrary code… | ||
| CVE-2026-0662 | Hig | 0.51 | 7.8 | 0.00 | Feb 4, 2026 | A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current process due to an Untrusted Search Path being utilized. | ||
| CVE-2025-12793 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2026 | An uncontrolled DLL loading path vulnerability exists in AsusSoftwareManagerAgent. A local attacker may influence the application to load a DLL from an attacker-controlled location, potentially resulting in arbitrary code execution. Refer to the ' Security Update for MyASUS'… | ||
| CVE-2025-67722 | Hig | 0.51 | 7.8 | 0.00 | Dec 16, 2025 | FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to versions 16.0.45 and 17.0.24 of the FreePBX framework, an authenticated local privilege escalation exists in the deprecated FreePBX startup script `amportal`. In the deprecated… | ||
| CVE-2025-64785 | Hig | 0.51 | 7.8 | 0.00 | Dec 9, 2025 | Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a… | ||
| CVE-2025-60718 | Hig | 0.51 | 7.8 | 0.00 | Nov 11, 2025 | Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-5039 | Hig | 0.51 | 7.8 | 0.00 | Jul 24, 2025 | A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized. | ||
| CVE-2025-5335 | Hig | 0.51 | 7.8 | 0.00 | Jun 10, 2025 | A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the Autodesk Installer application. Exploitation of this vulnerability may lead to code execution. | ||
| CVE-2024-12168 | Hig | 0.51 | 7.8 | 0.00 | Jun 2, 2025 | Yandex Telemost for Desktop before 2.7.0 has a DLL Hijacking Vulnerability because an untrusted search path is used. | ||
| CVE-2025-2501 | Hig | 0.51 | 7.8 | 0.00 | May 30, 2025 | An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges. | ||
| CVE-2025-4802 | Hig | 0.51 | 7.8 | 0.01 | May 16, 2025 | Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or… | ||
| CVE-2025-27743 | Hig | 0.51 | 7.8 | 0.01 | Apr 8, 2025 | Untrusted search path in System Center allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-27167 | Hig | 0.51 | 7.8 | 0.00 | Mar 11, 2025 | Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute their own programs, access unauthorized data files, or modify configuration in unexpected ways. If the application uses a search path to… | ||
| CVE-2025-0707 | Hig | 0.51 | 7.8 | 0.00 | Jan 24, 2025 | A vulnerability was found in Rise Group Rise Mode Temp CPU 2.1. It has been classified as critical. This affects an unknown part in the library CRYPTBASE.dll of the component Startup. The manipulation leads to untrusted search path. The attack needs to be approached locally. | ||
| CVE-2020-8094 | Hig | 0.51 | 7.8 | 0.00 | Jan 15, 2025 | An untrusted search path vulnerability in testinitsigs.exe as used in Bitdefender Antivirus Free 2020 allows a low-privilege attacker to execute code as SYSTEM via a specially crafted DLL file. | ||
| CVE-2025-21365 | Hig | 0.51 | 7.8 | 0.01 | Jan 14, 2025 | Microsoft Office Remote Code Execution Vulnerability |
- risk 0.51cvss 7.8epss 0.00
A vulnerability exists in the chroot utility of uutils coreutils when using the --userspec option. The utility resolves the user specification via getpwnam() after entering the chroot but before dropping root privileges. On glibc-based systems, this can trigger the Name Service…
- risk 0.51cvss 7.8epss 0.00
ScreenToGif is a screen recording tool. In versions from 2.42.1 and prior, ScreenToGif is vulnerable to DLL sideloading via version.dll . When the portable executable is run from a user-writable directory, it loads version.dll from the application directory instead of the…
- risk 0.51cvss 7.8epss 0.01
Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a crafted DLL file in the same directory as the program, thereby executing arbitrary code.
- risk 0.51cvss 7.8epss 0.00
SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, the PDF reader allows execution of a malicious binary (explorer.exe) located in the same directory as the opened PDF when the user clicks File → “Show in folder”. This behavior leads to arbitrary code…
- risk 0.51cvss 7.8epss 0.00
A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current process due to an Untrusted Search Path being utilized.
- risk 0.51cvss 7.8epss 0.00
An uncontrolled DLL loading path vulnerability exists in AsusSoftwareManagerAgent. A local attacker may influence the application to load a DLL from an attacker-controlled location, potentially resulting in arbitrary code execution. Refer to the ' Security Update for MyASUS'…
- risk 0.51cvss 7.8epss 0.00
FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to versions 16.0.45 and 17.0.24 of the FreePBX framework, an authenticated local privilege escalation exists in the deprecated FreePBX startup script `amportal`. In the deprecated…
- risk 0.51cvss 7.8epss 0.00
Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a…
- risk 0.51cvss 7.8epss 0.00
Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.
- risk 0.51cvss 7.8epss 0.00
A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the Autodesk Installer application. Exploitation of this vulnerability may lead to code execution.
- risk 0.51cvss 7.8epss 0.00
Yandex Telemost for Desktop before 2.7.0 has a DLL Hijacking Vulnerability because an untrusted search path is used.
- risk 0.51cvss 7.8epss 0.00
An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.
- risk 0.51cvss 7.8epss 0.01
Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or…
- risk 0.51cvss 7.8epss 0.01
Untrusted search path in System Center allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute their own programs, access unauthorized data files, or modify configuration in unexpected ways. If the application uses a search path to…
- risk 0.51cvss 7.8epss 0.00
A vulnerability was found in Rise Group Rise Mode Temp CPU 2.1. It has been classified as critical. This affects an unknown part in the library CRYPTBASE.dll of the component Startup. The manipulation leads to untrusted search path. The attack needs to be approached locally.
- risk 0.51cvss 7.8epss 0.00
An untrusted search path vulnerability in testinitsigs.exe as used in Bitdefender Antivirus Free 2020 allows a low-privilege attacker to execute code as SYSTEM via a specially crafted DLL file.
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Remote Code Execution Vulnerability