VYPR

CWE-426

Untrusted Search Path

BaseStableLikelihood: High

Description

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-38

CVEs mapped to this weakness (672)

page 7 of 34
  • CVE-2024-21325HigJan 9, 2024
    risk 0.51cvss 7.8epss 0.01

    Microsoft Printer Metadata Troubleshooter Tool Remote Code Execution Vulnerability

  • CVE-2023-41840HigNov 14, 2023
    risk 0.51cvss 7.8epss 0.00

    A untrusted search path vulnerability in Fortinet FortiClientWindows 7.0.9 allows an attacker to perform a DLL Hijack attack via a malicious OpenSSL engine library in the search path.

  • CVE-2023-36422HigNov 14, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft Windows Defender Elevation of Privilege Vulnerability

  • CVE-2023-36393HigNov 14, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows User Interface Application Core Remote Code Execution Vulnerability

  • CVE-2021-26738HigOct 23, 2023
    risk 0.51cvss 7.8epss 0.00

    Zscaler Client Connector for macOS prior to 3.7 had an unquoted search path vulnerability via the PATH variable. A local adversary may be able to execute code with root privileges.

  • CVE-2023-41766HigOct 10, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

  • CVE-2023-4736HigSep 2, 2023
    risk 0.51cvss 7.8epss 0.00

    Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833.

  • CVE-2023-39212HigAug 8, 2023
    risk 0.51cvss 7.9epss 0.00

    Untrusted search path in Zoom Rooms for Windows before version 5.15.5 may allow an authenticated user to enable a denial of service via local access.

  • CVE-2023-36898HigAug 8, 2023
    risk 0.51cvss 7.8epss 0.01

    Tablet Windows User Interface Application Core Remote Code Execution Vulnerability

  • CVE-2023-35343HigJul 11, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Geolocation Service Remote Code Execution Vulnerability

  • CVE-2023-34145HigJun 26, 2023
    risk 0.51cvss 7.8epss 0.00

    An untrusted search path vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate their privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged…

  • CVE-2023-34144HigJun 26, 2023
    risk 0.51cvss 7.8epss 0.00

    An untrusted search path vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate their privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged…

  • CVE-2023-27771HigApr 4, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue found in Wondershare Technology Co.,Ltd Creative Centerr v.1.0.8 allows a remote attacker to execute arbitrary commands via the wondershareCC_setup_full10819.exe file.

  • CVE-2023-27770HigApr 4, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue found in Wondershare Technology Co.,Ltd Edraw-max v.12.0.4 allows a remote attacker to execute arbitrary commands via the edraw-max_setup_full5371.exe file.

  • CVE-2023-27769HigApr 4, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue found in Wondershare Technology Co.,Ltd PDF Reader v.1.0.1 allows a remote attacker to execute arbitrary commands via the pdfreader_setup_full13143.exe file.

  • CVE-2023-27768HigApr 4, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue found in Wondershare Technology Co.,Ltd PDFelement v9.1.1 allows a remote attacker to execute arbitrary commands via the pdfelement-pro_setup_full5239.exe file.

  • CVE-2023-27767HigApr 4, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue found in Wondershare Technology Co.,Ltd Dr.Fone v.12.4.9 allows a remote attacker to execute arbitrary commands via the drfone_setup_full3360.exe file.

  • CVE-2023-27766HigApr 4, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue found in Wondershare Technology Co.,Ltd Anireel 1.5.4 allows a remote attacker to execute arbitrary commands via the anireel_setup_full9589.exe file.

  • CVE-2023-27765HigApr 4, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue found in Wondershare Technology Co.,Ltd Recoverit v.10.6.3 allows a remote attacker to execute arbitrary commands via the recoverit_setup_full4134.exe file.

  • CVE-2023-27764HigApr 4, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue found in Wondershare Technology Co.,Ltd Repairit v.3.5.4 allows a remote attacker to execute arbitrary commands via the repairit_setup_full5913.exe file.