CWE-426
Untrusted Search Path
Description
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-38
CVEs mapped to this weakness (695)
page 6 of 35| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-64785 | Hig | 0.51 | 7.8 | 0.00 | Dec 9, 2025 | Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a… | ||
| CVE-2025-60718 | Hig | 0.51 | 7.8 | 0.00 | Nov 11, 2025 | Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-5039 | Hig | 0.51 | 7.8 | 0.00 | Jul 24, 2025 | A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized. | ||
| CVE-2025-5335 | Hig | 0.51 | 7.8 | 0.00 | Jun 10, 2025 | A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the Autodesk Installer application. Exploitation of this vulnerability may lead to code execution. | ||
| CVE-2024-12168 | Hig | 0.51 | 7.8 | 0.00 | Jun 2, 2025 | Yandex Telemost for Desktop before 2.7.0 has a DLL Hijacking Vulnerability because an untrusted search path is used. | ||
| CVE-2025-2501 | Hig | 0.51 | 7.8 | 0.00 | May 30, 2025 | An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges. | ||
| CVE-2025-4802 | Hig | 0.51 | 7.8 | 0.01 | May 16, 2025 | Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or… | ||
| CVE-2025-27743 | Hig | 0.51 | 7.8 | 0.01 | Apr 8, 2025 | Untrusted search path in System Center allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-27167 | Hig | 0.51 | 7.8 | 0.00 | Mar 11, 2025 | Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute their own programs, access unauthorized data files, or modify configuration in unexpected ways. If the application uses a search path to… | ||
| CVE-2025-0707 | Hig | 0.51 | 7.8 | 0.00 | Jan 24, 2025 | A vulnerability was found in Rise Group Rise Mode Temp CPU 2.1. It has been classified as critical. This affects an unknown part in the library CRYPTBASE.dll of the component Startup. The manipulation leads to untrusted search path. The attack needs to be approached locally. | ||
| CVE-2020-8094 | Hig | 0.51 | 7.8 | 0.00 | Jan 15, 2025 | An untrusted search path vulnerability in testinitsigs.exe as used in Bitdefender Antivirus Free 2020 allows a low-privilege attacker to execute code as SYSTEM via a specially crafted DLL file. | ||
| CVE-2025-21365 | Hig | 0.51 | 7.8 | 0.01 | Jan 14, 2025 | Microsoft Office Remote Code Execution Vulnerability | ||
| CVE-2024-11454 | Hig | 0.51 | 7.8 | 0.00 | Dec 9, 2024 | A maliciously crafted DLL file, when placed in the same directory as an RVT file could be loaded by Autodesk Revit, and execute arbitrary code in the context of the current process due to an untrusted search patch being utilized. | ||
| CVE-2023-1521 | Hig | 0.51 | 7.8 | 0.00 | Nov 26, 2024 | On Linux the sccache client can execute arbitrary code with the privileges of a local sccache server, by preloading the code in a shared library passed to LD_PRELOAD. If the server is run as root (which is the default when installing the snap package… | ||
| CVE-2024-49515 | Hig | 0.51 | 7.8 | 0.00 | Nov 12, 2024 | Substance3D - Painter versions 10.1.0 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code. If the application uses a search path to locate critical resources such as programs, then an attacker could modify that… | ||
| CVE-2024-49043 | Hig | 0.51 | 7.8 | 0.01 | Nov 12, 2024 | Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability | ||
| CVE-2024-47906 | Hig | 0.51 | 7.8 | 0.00 | Nov 12, 2024 | Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.2 (Not Applicable to 9.1Rx) allows a local authenticated attacker to escalate privileges. | ||
| CVE-2024-7995 | Hig | 0.51 | 7.8 | 0.00 | Nov 5, 2024 | A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the VRED Design application. Exploitation of this vulnerability may lead to code execution. | ||
| CVE-2024-47422 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2024 | Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Untrusted Search Path vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by inserting a malicious path into the search directories, which the application… | ||
| CVE-2024-43616 | Hig | 0.51 | 7.8 | 0.01 | Oct 8, 2024 | Microsoft Office Remote Code Execution Vulnerability |
- risk 0.51cvss 7.8epss 0.00
Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a…
- risk 0.51cvss 7.8epss 0.00
Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.
- risk 0.51cvss 7.8epss 0.00
A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the Autodesk Installer application. Exploitation of this vulnerability may lead to code execution.
- risk 0.51cvss 7.8epss 0.00
Yandex Telemost for Desktop before 2.7.0 has a DLL Hijacking Vulnerability because an untrusted search path is used.
- risk 0.51cvss 7.8epss 0.00
An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.
- risk 0.51cvss 7.8epss 0.01
Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or…
- risk 0.51cvss 7.8epss 0.01
Untrusted search path in System Center allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute their own programs, access unauthorized data files, or modify configuration in unexpected ways. If the application uses a search path to…
- risk 0.51cvss 7.8epss 0.00
A vulnerability was found in Rise Group Rise Mode Temp CPU 2.1. It has been classified as critical. This affects an unknown part in the library CRYPTBASE.dll of the component Startup. The manipulation leads to untrusted search path. The attack needs to be approached locally.
- risk 0.51cvss 7.8epss 0.00
An untrusted search path vulnerability in testinitsigs.exe as used in Bitdefender Antivirus Free 2020 allows a low-privilege attacker to execute code as SYSTEM via a specially crafted DLL file.
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
A maliciously crafted DLL file, when placed in the same directory as an RVT file could be loaded by Autodesk Revit, and execute arbitrary code in the context of the current process due to an untrusted search patch being utilized.
- risk 0.51cvss 7.8epss 0.00
On Linux the sccache client can execute arbitrary code with the privileges of a local sccache server, by preloading the code in a shared library passed to LD_PRELOAD. If the server is run as root (which is the default when installing the snap package…
- risk 0.51cvss 7.8epss 0.00
Substance3D - Painter versions 10.1.0 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code. If the application uses a search path to locate critical resources such as programs, then an attacker could modify that…
- risk 0.51cvss 7.8epss 0.01
Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.2 (Not Applicable to 9.1Rx) allows a local authenticated attacker to escalate privileges.
- risk 0.51cvss 7.8epss 0.00
A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the VRED Design application. Exploitation of this vulnerability may lead to code execution.
- risk 0.51cvss 7.8epss 0.00
Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Untrusted Search Path vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by inserting a malicious path into the search directories, which the application…
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Remote Code Execution Vulnerability