VYPR

CWE-426

Untrusted Search Path

BaseStableLikelihood: High

Description

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-38

CVEs mapped to this weakness (691)

page 7 of 35
  • CVE-2024-6473HigSep 3, 2024
    risk 0.51cvss 7.8epss 0.01

    Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.

  • CVE-2024-5623HigAug 29, 2024
    risk 0.51cvss 7.8epss 0.00

    An untrusted search path vulnerability in B&R APROL <= R 4.4-00P3 may be used by an authenticated local attacker to get other users to execute arbitrary code under their privileges.

  • CVE-2024-5622HigAug 29, 2024
    risk 0.51cvss 7.8epss 0.00

    An untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL <= R 4.2.-07P3 and <= R 4.4-00P3 may allow an authenticated local attacker to execute arbitrary code with elevated privileges.

  • CVE-2024-7886HigAug 16, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been found in Scooter Software Beyond Compare up to 3.3.5.15075 and classified as critical. Affected by this vulnerability is an unknown functionality in the library 7zxa.dll. The manipulation leads to uncontrolled search path. Attacking locally is a…

  • CVE-2024-41865HigAug 14, 2024
    risk 0.51cvss 7.8epss 0.00

    Dimension versions 3.4.11 and earlier are affected by an Untrusted Search Path vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by inserting a malicious file into the search path, which the application might execute instead…

  • CVE-2024-6080HigJun 17, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability classified as critical was found in Intelbras InControl 2.21.56. This vulnerability affects unknown code of the component incontrolWebcam Service. The manipulation leads to unquoted search path. Local access is required to approach this attack. The exploit has…

  • CVE-2024-30100HigJun 11, 2024
    risk 0.51cvss 7.8epss 0.01

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2024-28133HigMay 14, 2024
    risk 0.51cvss 7.8epss 0.00

    A local low privileged attacker can use an untrusted search path in a CHARX system utility to gain root privileges. 

  • CVE-2024-20693HigApr 9, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2024-20754HigMar 18, 2024
    risk 0.51cvss 7.8epss 0.00

    Lightroom Desktop versions 7.1.2 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. If the application uses a search path to locate critical resources such as programs, then an…

  • CVE-2024-21325HigJan 9, 2024
    risk 0.51cvss 7.8epss 0.01

    Microsoft Printer Metadata Troubleshooter Tool Remote Code Execution Vulnerability

  • CVE-2023-41840HigNov 14, 2023
    risk 0.51cvss 7.8epss 0.00

    A untrusted search path vulnerability in Fortinet FortiClientWindows 7.0.9 allows an attacker to perform a DLL Hijack attack via a malicious OpenSSL engine library in the search path.

  • CVE-2023-36422HigNov 14, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft Windows Defender Elevation of Privilege Vulnerability

  • CVE-2023-36393HigNov 14, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows User Interface Application Core Remote Code Execution Vulnerability

  • CVE-2021-26738HigOct 23, 2023
    risk 0.51cvss 7.8epss 0.00

    Zscaler Client Connector for macOS prior to 3.7 had an unquoted search path vulnerability via the PATH variable. A local adversary may be able to execute code with root privileges.

  • CVE-2023-41766HigOct 10, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

  • CVE-2023-4736HigSep 2, 2023
    risk 0.51cvss 7.8epss 0.01

    Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833.

  • CVE-2023-39212HigAug 8, 2023
    risk 0.51cvss 7.9epss 0.00

    Untrusted search path in Zoom Rooms for Windows before version 5.15.5 may allow an authenticated user to enable a denial of service via local access.

  • CVE-2023-36898HigAug 8, 2023
    risk 0.51cvss 7.8epss 0.01

    Tablet Windows User Interface Application Core Remote Code Execution Vulnerability

  • CVE-2023-35343HigJul 11, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Geolocation Service Remote Code Execution Vulnerability