VYPR

CWE-426

Untrusted Search Path

BaseStableLikelihood: High

Description

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-38

CVEs mapped to this weakness (672)

page 6 of 34
  • CVE-2023-1521HigNov 26, 2024
    risk 0.51cvss 7.8epss 0.00

    On Linux the sccache client can execute arbitrary code with the privileges of a local sccache server, by preloading the code in a shared library passed to LD_PRELOAD. If the server is run as root (which is the default when installing the snap package…

  • CVE-2024-49515HigNov 12, 2024
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Painter versions 10.1.0 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code. If the application uses a search path to locate critical resources such as programs, then an attacker could modify that…

  • CVE-2024-49043HigNov 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability

  • CVE-2024-47906HigNov 12, 2024
    risk 0.51cvss 7.8epss 0.00

    Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.2 (Not Applicable to 9.1Rx) allows a local authenticated attacker to escalate privileges.

  • CVE-2024-7995HigNov 5, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the VRED Design application. Exploitation of this vulnerability may lead to code execution.

  • CVE-2024-47422HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.00

    Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Untrusted Search Path vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by inserting a malicious path into the search directories, which the application…

  • CVE-2024-43616HigOct 8, 2024
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Remote Code Execution Vulnerability

  • CVE-2024-43576HigOct 8, 2024
    risk 0.51cvss 7.8epss 0.00

    Microsoft Office Remote Code Execution Vulnerability

  • CVE-2024-9325HigSep 29, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability classified as critical has been found in Intelbras InControl up to 2.21.56. This affects an unknown part of the file C:\Program Files (x86)\Intelbras\Incontrol Cliente\incontrol_webcam\incontrol-service-watchdog.exe. The manipulation leads to unquoted search…

  • CVE-2024-6473HigSep 3, 2024
    risk 0.51cvss 7.8epss 0.01

    Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.

  • CVE-2024-5623HigAug 29, 2024
    risk 0.51cvss 7.8epss 0.00

    An untrusted search path vulnerability in B&R APROL <= R 4.4-00P3 may be used by an authenticated local attacker to get other users to execute arbitrary code under their privileges.

  • CVE-2024-5622HigAug 29, 2024
    risk 0.51cvss 7.8epss 0.00

    An untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL <= R 4.2.-07P3 and <= R 4.4-00P3 may allow an authenticated local attacker to execute arbitrary code with elevated privileges.

  • CVE-2024-7886HigAug 16, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been found in Scooter Software Beyond Compare up to 3.3.5.15075 and classified as critical. Affected by this vulnerability is an unknown functionality in the library 7zxa.dll. The manipulation leads to uncontrolled search path. Attacking locally is a…

  • CVE-2024-41865HigAug 14, 2024
    risk 0.51cvss 7.8epss 0.00

    Dimension versions 3.4.11 and earlier are affected by an Untrusted Search Path vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by inserting a malicious file into the search path, which the application might execute instead…

  • CVE-2024-6080HigJun 17, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability classified as critical was found in Intelbras InControl 2.21.56. This vulnerability affects unknown code of the component incontrolWebcam Service. The manipulation leads to unquoted search path. Local access is required to approach this attack. The exploit has…

  • CVE-2024-30100HigJun 11, 2024
    risk 0.51cvss 7.8epss 0.01

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2024-28133HigMay 14, 2024
    risk 0.51cvss 7.8epss 0.00

    A local low privileged attacker can use an untrusted search path in a CHARX system utility to gain root privileges. 

  • CVE-2024-20693HigApr 9, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2024-20754HigMar 18, 2024
    risk 0.51cvss 7.8epss 0.00

    Lightroom Desktop versions 7.1.2 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. If the application uses a search path to locate critical resources such as programs, then an…

  • CVE-2024-21325HigJan 9, 2024
    risk 0.51cvss 7.8epss 0.01

    Microsoft Printer Metadata Troubleshooter Tool Remote Code Execution Vulnerability