CWE-426
Untrusted Search Path
Description
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-38
CVEs mapped to this weakness (691)
page 7 of 35| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-6473 | Hig | 0.51 | 7.8 | 0.01 | Sep 3, 2024 | Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used. | ||
| CVE-2024-5623 | Hig | 0.51 | 7.8 | 0.00 | Aug 29, 2024 | An untrusted search path vulnerability in B&R APROL <= R 4.4-00P3 may be used by an authenticated local attacker to get other users to execute arbitrary code under their privileges. | ||
| CVE-2024-5622 | Hig | 0.51 | 7.8 | 0.00 | Aug 29, 2024 | An untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL <= R 4.2.-07P3 and <= R 4.4-00P3 may allow an authenticated local attacker to execute arbitrary code with elevated privileges. | ||
| CVE-2024-7886 | Hig | 0.51 | 7.8 | 0.00 | Aug 16, 2024 | A vulnerability has been found in Scooter Software Beyond Compare up to 3.3.5.15075 and classified as critical. Affected by this vulnerability is an unknown functionality in the library 7zxa.dll. The manipulation leads to uncontrolled search path. Attacking locally is a… | ||
| CVE-2024-41865 | Hig | 0.51 | 7.8 | 0.00 | Aug 14, 2024 | Dimension versions 3.4.11 and earlier are affected by an Untrusted Search Path vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by inserting a malicious file into the search path, which the application might execute instead… | ||
| CVE-2024-6080 | Hig | 0.51 | 7.8 | 0.00 | Jun 17, 2024 | A vulnerability classified as critical was found in Intelbras InControl 2.21.56. This vulnerability affects unknown code of the component incontrolWebcam Service. The manipulation leads to unquoted search path. Local access is required to approach this attack. The exploit has… | ||
| CVE-2024-30100 | Hig | 0.51 | 7.8 | 0.01 | Jun 11, 2024 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2024-28133 | Hig | 0.51 | 7.8 | 0.00 | May 14, 2024 | A local low privileged attacker can use an untrusted search path in a CHARX system utility to gain root privileges. | ||
| CVE-2024-20693 | Hig | 0.51 | 7.8 | 0.01 | Apr 9, 2024 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2024-20754 | Hig | 0.51 | 7.8 | 0.00 | Mar 18, 2024 | Lightroom Desktop versions 7.1.2 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. If the application uses a search path to locate critical resources such as programs, then an… | ||
| CVE-2024-21325 | Hig | 0.51 | 7.8 | 0.01 | Jan 9, 2024 | Microsoft Printer Metadata Troubleshooter Tool Remote Code Execution Vulnerability | ||
| CVE-2023-41840 | Hig | 0.51 | 7.8 | 0.00 | Nov 14, 2023 | A untrusted search path vulnerability in Fortinet FortiClientWindows 7.0.9 allows an attacker to perform a DLL Hijack attack via a malicious OpenSSL engine library in the search path. | ||
| CVE-2023-36422 | Hig | 0.51 | 7.8 | 0.01 | Nov 14, 2023 | Microsoft Windows Defender Elevation of Privilege Vulnerability | ||
| CVE-2023-36393 | Hig | 0.51 | 7.8 | 0.01 | Nov 14, 2023 | Windows User Interface Application Core Remote Code Execution Vulnerability | ||
| CVE-2021-26738 | Hig | 0.51 | 7.8 | 0.00 | Oct 23, 2023 | Zscaler Client Connector for macOS prior to 3.7 had an unquoted search path vulnerability via the PATH variable. A local adversary may be able to execute code with root privileges. | ||
| CVE-2023-41766 | Hig | 0.51 | 7.8 | 0.01 | Oct 10, 2023 | Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | ||
| CVE-2023-4736 | Hig | 0.51 | 7.8 | 0.01 | Sep 2, 2023 | Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833. | ||
| CVE-2023-39212 | Hig | 0.51 | 7.9 | 0.00 | Aug 8, 2023 | Untrusted search path in Zoom Rooms for Windows before version 5.15.5 may allow an authenticated user to enable a denial of service via local access. | ||
| CVE-2023-36898 | Hig | 0.51 | 7.8 | 0.01 | Aug 8, 2023 | Tablet Windows User Interface Application Core Remote Code Execution Vulnerability | ||
| CVE-2023-35343 | Hig | 0.51 | 7.8 | 0.01 | Jul 11, 2023 | Windows Geolocation Service Remote Code Execution Vulnerability |
- risk 0.51cvss 7.8epss 0.01
Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.
- risk 0.51cvss 7.8epss 0.00
An untrusted search path vulnerability in B&R APROL <= R 4.4-00P3 may be used by an authenticated local attacker to get other users to execute arbitrary code under their privileges.
- risk 0.51cvss 7.8epss 0.00
An untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL <= R 4.2.-07P3 and <= R 4.4-00P3 may allow an authenticated local attacker to execute arbitrary code with elevated privileges.
- risk 0.51cvss 7.8epss 0.00
A vulnerability has been found in Scooter Software Beyond Compare up to 3.3.5.15075 and classified as critical. Affected by this vulnerability is an unknown functionality in the library 7zxa.dll. The manipulation leads to uncontrolled search path. Attacking locally is a…
- risk 0.51cvss 7.8epss 0.00
Dimension versions 3.4.11 and earlier are affected by an Untrusted Search Path vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by inserting a malicious file into the search path, which the application might execute instead…
- risk 0.51cvss 7.8epss 0.00
A vulnerability classified as critical was found in Intelbras InControl 2.21.56. This vulnerability affects unknown code of the component incontrolWebcam Service. The manipulation leads to unquoted search path. Local access is required to approach this attack. The exploit has…
- risk 0.51cvss 7.8epss 0.01
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
A local low privileged attacker can use an untrusted search path in a CHARX system utility to gain root privileges.
- risk 0.51cvss 7.8epss 0.01
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Lightroom Desktop versions 7.1.2 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. If the application uses a search path to locate critical resources such as programs, then an…
- risk 0.51cvss 7.8epss 0.01
Microsoft Printer Metadata Troubleshooter Tool Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
A untrusted search path vulnerability in Fortinet FortiClientWindows 7.0.9 allows an attacker to perform a DLL Hijack attack via a malicious OpenSSL engine library in the search path.
- risk 0.51cvss 7.8epss 0.01
Microsoft Windows Defender Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows User Interface Application Core Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
Zscaler Client Connector for macOS prior to 3.7 had an unquoted search path vulnerability via the PATH variable. A local adversary may be able to execute code with root privileges.
- risk 0.51cvss 7.8epss 0.01
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833.
- risk 0.51cvss 7.9epss 0.00
Untrusted search path in Zoom Rooms for Windows before version 5.15.5 may allow an authenticated user to enable a denial of service via local access.
- risk 0.51cvss 7.8epss 0.01
Tablet Windows User Interface Application Core Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Geolocation Service Remote Code Execution Vulnerability