CWE-426
Untrusted Search Path
Description
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-38
CVEs mapped to this weakness (691)
page 8 of 35| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-34145 | Hig | 0.51 | 7.8 | 0.00 | Jun 26, 2023 | An untrusted search path vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate their privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged… | ||
| CVE-2023-34144 | Hig | 0.51 | 7.8 | 0.00 | Jun 26, 2023 | An untrusted search path vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate their privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged… | ||
| CVE-2023-27771 | Hig | 0.51 | 7.8 | 0.00 | Apr 4, 2023 | An issue found in Wondershare Technology Co.,Ltd Creative Centerr v.1.0.8 allows a remote attacker to execute arbitrary commands via the wondershareCC_setup_full10819.exe file. | ||
| CVE-2023-27770 | Hig | 0.51 | 7.8 | 0.00 | Apr 4, 2023 | An issue found in Wondershare Technology Co.,Ltd Edraw-max v.12.0.4 allows a remote attacker to execute arbitrary commands via the edraw-max_setup_full5371.exe file. | ||
| CVE-2023-27769 | Hig | 0.51 | 7.8 | 0.00 | Apr 4, 2023 | An issue found in Wondershare Technology Co.,Ltd PDF Reader v.1.0.1 allows a remote attacker to execute arbitrary commands via the pdfreader_setup_full13143.exe file. | ||
| CVE-2023-27768 | Hig | 0.51 | 7.8 | 0.00 | Apr 4, 2023 | An issue found in Wondershare Technology Co.,Ltd PDFelement v9.1.1 allows a remote attacker to execute arbitrary commands via the pdfelement-pro_setup_full5239.exe file. | ||
| CVE-2023-27767 | Hig | 0.51 | 7.8 | 0.00 | Apr 4, 2023 | An issue found in Wondershare Technology Co.,Ltd Dr.Fone v.12.4.9 allows a remote attacker to execute arbitrary commands via the drfone_setup_full3360.exe file. | ||
| CVE-2023-27766 | Hig | 0.51 | 7.8 | 0.00 | Apr 4, 2023 | An issue found in Wondershare Technology Co.,Ltd Anireel 1.5.4 allows a remote attacker to execute arbitrary commands via the anireel_setup_full9589.exe file. | ||
| CVE-2023-27765 | Hig | 0.51 | 7.8 | 0.00 | Apr 4, 2023 | An issue found in Wondershare Technology Co.,Ltd Recoverit v.10.6.3 allows a remote attacker to execute arbitrary commands via the recoverit_setup_full4134.exe file. | ||
| CVE-2023-27764 | Hig | 0.51 | 7.8 | 0.00 | Apr 4, 2023 | An issue found in Wondershare Technology Co.,Ltd Repairit v.3.5.4 allows a remote attacker to execute arbitrary commands via the repairit_setup_full5913.exe file. | ||
| CVE-2023-27763 | Hig | 0.51 | 7.8 | 0.00 | Apr 4, 2023 | An issue found in Wondershare Technology Co.,Ltd MobileTrans v.4.0.2 allows a remote attacker to execute arbitrary commands via the mobiletrans_setup_full5793.exe file. | ||
| CVE-2023-27762 | Hig | 0.51 | 7.8 | 0.00 | Apr 4, 2023 | An issue found in Wondershare Technology Co., Ltd DemoCreator v.6.0.0 allows a remote attacker to execute arbitrary commands via the democreator_setup_full7743.exe file. | ||
| CVE-2023-27761 | Hig | 0.51 | 7.8 | 0.00 | Apr 4, 2023 | An issue found in Wondershare Technology Co., Ltd UniConverter v.14.0.0 allows a remote attacker to execute arbitrary commands via the uniconverter14_64bit_setup_full14204.exe file. | ||
| CVE-2023-27760 | Hig | 0.51 | 7.8 | 0.00 | Apr 4, 2023 | An issue found in Wondershare Technology Co, Ltd Filmora v.12.0.9 allows a remote attacker to execute arbitrary commands via the filmora_setup_full846.exe. | ||
| CVE-2023-27759 | Hig | 0.51 | 7.8 | 0.00 | Apr 4, 2023 | An issue found in Wondershare Technology Co, Ltd Edrawmind v.10.0.6 allows a remote attacker to executea arbitrary commands via the WindowsCodescs.dll file. | ||
| CVE-2023-22368 | Hig | 0.51 | 7.8 | 0.00 | Feb 15, 2023 | Untrusted search path vulnerability in ELECOM Camera Assistant 1.00 and QuickFileDealer Ver.1.2.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | ||
| CVE-2023-21764 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | Microsoft Exchange Server Elevation of Privilege Vulnerability | ||
| CVE-2023-21763 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | Microsoft Exchange Server Elevation of Privilege Vulnerability | ||
| CVE-2021-3305 | Hig | 0.51 | 7.8 | 0.00 | Oct 18, 2022 | Beijing Feishu Technology Co., Ltd Feishu v3.40.3 was discovered to contain an untrusted search path vulnerability. | ||
| CVE-2022-36403 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2022 | Untrusted search path vulnerability in the installer of Device Software Manager prior to Ver.2.20.3.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. |
- risk 0.51cvss 7.8epss 0.00
An untrusted search path vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate their privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged…
- risk 0.51cvss 7.8epss 0.00
An untrusted search path vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate their privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged…
- risk 0.51cvss 7.8epss 0.00
An issue found in Wondershare Technology Co.,Ltd Creative Centerr v.1.0.8 allows a remote attacker to execute arbitrary commands via the wondershareCC_setup_full10819.exe file.
- risk 0.51cvss 7.8epss 0.00
An issue found in Wondershare Technology Co.,Ltd Edraw-max v.12.0.4 allows a remote attacker to execute arbitrary commands via the edraw-max_setup_full5371.exe file.
- risk 0.51cvss 7.8epss 0.00
An issue found in Wondershare Technology Co.,Ltd PDF Reader v.1.0.1 allows a remote attacker to execute arbitrary commands via the pdfreader_setup_full13143.exe file.
- risk 0.51cvss 7.8epss 0.00
An issue found in Wondershare Technology Co.,Ltd PDFelement v9.1.1 allows a remote attacker to execute arbitrary commands via the pdfelement-pro_setup_full5239.exe file.
- risk 0.51cvss 7.8epss 0.00
An issue found in Wondershare Technology Co.,Ltd Dr.Fone v.12.4.9 allows a remote attacker to execute arbitrary commands via the drfone_setup_full3360.exe file.
- risk 0.51cvss 7.8epss 0.00
An issue found in Wondershare Technology Co.,Ltd Anireel 1.5.4 allows a remote attacker to execute arbitrary commands via the anireel_setup_full9589.exe file.
- risk 0.51cvss 7.8epss 0.00
An issue found in Wondershare Technology Co.,Ltd Recoverit v.10.6.3 allows a remote attacker to execute arbitrary commands via the recoverit_setup_full4134.exe file.
- risk 0.51cvss 7.8epss 0.00
An issue found in Wondershare Technology Co.,Ltd Repairit v.3.5.4 allows a remote attacker to execute arbitrary commands via the repairit_setup_full5913.exe file.
- risk 0.51cvss 7.8epss 0.00
An issue found in Wondershare Technology Co.,Ltd MobileTrans v.4.0.2 allows a remote attacker to execute arbitrary commands via the mobiletrans_setup_full5793.exe file.
- risk 0.51cvss 7.8epss 0.00
An issue found in Wondershare Technology Co., Ltd DemoCreator v.6.0.0 allows a remote attacker to execute arbitrary commands via the democreator_setup_full7743.exe file.
- risk 0.51cvss 7.8epss 0.00
An issue found in Wondershare Technology Co., Ltd UniConverter v.14.0.0 allows a remote attacker to execute arbitrary commands via the uniconverter14_64bit_setup_full14204.exe file.
- risk 0.51cvss 7.8epss 0.00
An issue found in Wondershare Technology Co, Ltd Filmora v.12.0.9 allows a remote attacker to execute arbitrary commands via the filmora_setup_full846.exe.
- risk 0.51cvss 7.8epss 0.00
An issue found in Wondershare Technology Co, Ltd Edrawmind v.10.0.6 allows a remote attacker to executea arbitrary commands via the WindowsCodescs.dll file.
- risk 0.51cvss 7.8epss 0.00
Untrusted search path vulnerability in ELECOM Camera Assistant 1.00 and QuickFileDealer Ver.1.2.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
- risk 0.51cvss 7.8epss 0.01
Microsoft Exchange Server Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Exchange Server Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Beijing Feishu Technology Co., Ltd Feishu v3.40.3 was discovered to contain an untrusted search path vulnerability.
- risk 0.51cvss 7.8epss 0.00
Untrusted search path vulnerability in the installer of Device Software Manager prior to Ver.2.20.3.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.