CWE-426
Untrusted Search Path
Description
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-38
CVEs mapped to this weakness (672)
page 8 of 34| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-27763 | Hig | 0.51 | 7.8 | 0.00 | Apr 4, 2023 | An issue found in Wondershare Technology Co.,Ltd MobileTrans v.4.0.2 allows a remote attacker to execute arbitrary commands via the mobiletrans_setup_full5793.exe file. | ||
| CVE-2023-27762 | Hig | 0.51 | 7.8 | 0.00 | Apr 4, 2023 | An issue found in Wondershare Technology Co., Ltd DemoCreator v.6.0.0 allows a remote attacker to execute arbitrary commands via the democreator_setup_full7743.exe file. | ||
| CVE-2023-27761 | Hig | 0.51 | 7.8 | 0.00 | Apr 4, 2023 | An issue found in Wondershare Technology Co., Ltd UniConverter v.14.0.0 allows a remote attacker to execute arbitrary commands via the uniconverter14_64bit_setup_full14204.exe file. | ||
| CVE-2023-27760 | Hig | 0.51 | 7.8 | 0.00 | Apr 4, 2023 | An issue found in Wondershare Technology Co, Ltd Filmora v.12.0.9 allows a remote attacker to execute arbitrary commands via the filmora_setup_full846.exe. | ||
| CVE-2023-27759 | Hig | 0.51 | 7.8 | 0.00 | Apr 4, 2023 | An issue found in Wondershare Technology Co, Ltd Edrawmind v.10.0.6 allows a remote attacker to executea arbitrary commands via the WindowsCodescs.dll file. | ||
| CVE-2023-22368 | Hig | 0.51 | 7.8 | 0.00 | Feb 15, 2023 | Untrusted search path vulnerability in ELECOM Camera Assistant 1.00 and QuickFileDealer Ver.1.2.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | ||
| CVE-2023-21764 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | Microsoft Exchange Server Elevation of Privilege Vulnerability | ||
| CVE-2023-21763 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | Microsoft Exchange Server Elevation of Privilege Vulnerability | ||
| CVE-2021-3305 | Hig | 0.51 | 7.8 | 0.00 | Oct 18, 2022 | Beijing Feishu Technology Co., Ltd Feishu v3.40.3 was discovered to contain an untrusted search path vulnerability. | ||
| CVE-2022-36403 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2022 | Untrusted search path vulnerability in the installer of Device Software Manager prior to Ver.2.20.3.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | ||
| CVE-2021-36666 | Hig | 0.51 | 7.8 | 0.00 | Jul 12, 2022 | An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission. | ||
| CVE-2022-25366 | Hig | 0.51 | 7.8 | 0.01 | Feb 19, 2022 | Cryptomator through 1.6.5 allows DYLIB injection because, although it has the flag 0x1000 for Hardened Runtime, it has the com.apple.security.cs.disable-library-validation and com.apple.security.cs.allow-dyld-environment-variables entitlements. An attacker can exploit this by… | ||
| CVE-2021-45975 | Hig | 0.51 | 7.8 | 0.01 | Jan 26, 2022 | In ListCheck.exe in Acer Care Center 4.x before 4.00.3038, a vulnerability in the loading mechanism of Windows DLLs could allow a local attacker to perform a DLL hijacking attack. This vulnerability is due to incorrect handling of directory search paths at run time. An attacker… | ||
| CVE-2021-33063 | Hig | 0.51 | 7.8 | 0.00 | Nov 17, 2021 | Uncontrolled search path in the Intel(R) RealSense(TM) D400 Series UWP driver for Windows 10 before version 6.1.160.22 may allow an authenticated user to potentially enable escalation of privilege via local access. | ||
| CVE-2020-12892 | Hig | 0.51 | 7.8 | 0.00 | Nov 15, 2021 | An untrusted search path in AMD Radeon settings Installer may lead to a privilege escalation or unauthorized code execution. | ||
| CVE-2021-26557 | Hig | 0.51 | 7.8 | 0.00 | Oct 7, 2021 | When Octopus Tentacle is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access. | ||
| CVE-2021-26556 | Hig | 0.51 | 7.8 | 0.00 | Oct 7, 2021 | When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access. | ||
| CVE-2021-36297 | Hig | 0.51 | 7.8 | 0.00 | Sep 28, 2021 | SupportAssist Client version 3.8 and 3.9 contains an Untrusted search path vulnerability that allows attackers to load an arbitrary .dll file via .dll planting/hijacking, only by a separate administrative action that is not a default part of the SOSInstallerTool.exe installation… | ||
| CVE-2021-25699 | Hig | 0.51 | 7.8 | 0.00 | Jul 21, 2021 | The OpenSSL component of the Teradici PCoIP Software Client prior to version 21.07.0 was compiled without the no-autoload-config option, which allowed an attacker to elevate to the privileges of the running process via placing a specially crafted dll in a build configuration… | ||
| CVE-2021-25698 | Hig | 0.51 | 7.8 | 0.00 | Jul 21, 2021 | The OpenSSL component of the Teradici PCoIP Standard Agent prior to version 21.07.0 was compiled without the no-autoload-config option, which allowed an attacker to elevate to the privileges of the running process via placing a specially crafted dll in a build configuration… |
- risk 0.51cvss 7.8epss 0.00
An issue found in Wondershare Technology Co.,Ltd MobileTrans v.4.0.2 allows a remote attacker to execute arbitrary commands via the mobiletrans_setup_full5793.exe file.
- risk 0.51cvss 7.8epss 0.00
An issue found in Wondershare Technology Co., Ltd DemoCreator v.6.0.0 allows a remote attacker to execute arbitrary commands via the democreator_setup_full7743.exe file.
- risk 0.51cvss 7.8epss 0.00
An issue found in Wondershare Technology Co., Ltd UniConverter v.14.0.0 allows a remote attacker to execute arbitrary commands via the uniconverter14_64bit_setup_full14204.exe file.
- risk 0.51cvss 7.8epss 0.00
An issue found in Wondershare Technology Co, Ltd Filmora v.12.0.9 allows a remote attacker to execute arbitrary commands via the filmora_setup_full846.exe.
- risk 0.51cvss 7.8epss 0.00
An issue found in Wondershare Technology Co, Ltd Edrawmind v.10.0.6 allows a remote attacker to executea arbitrary commands via the WindowsCodescs.dll file.
- risk 0.51cvss 7.8epss 0.00
Untrusted search path vulnerability in ELECOM Camera Assistant 1.00 and QuickFileDealer Ver.1.2.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
- risk 0.51cvss 7.8epss 0.01
Microsoft Exchange Server Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Exchange Server Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Beijing Feishu Technology Co., Ltd Feishu v3.40.3 was discovered to contain an untrusted search path vulnerability.
- risk 0.51cvss 7.8epss 0.00
Untrusted search path vulnerability in the installer of Device Software Manager prior to Ver.2.20.3.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
- risk 0.51cvss 7.8epss 0.00
An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission.
- risk 0.51cvss 7.8epss 0.01
Cryptomator through 1.6.5 allows DYLIB injection because, although it has the flag 0x1000 for Hardened Runtime, it has the com.apple.security.cs.disable-library-validation and com.apple.security.cs.allow-dyld-environment-variables entitlements. An attacker can exploit this by…
- risk 0.51cvss 7.8epss 0.01
In ListCheck.exe in Acer Care Center 4.x before 4.00.3038, a vulnerability in the loading mechanism of Windows DLLs could allow a local attacker to perform a DLL hijacking attack. This vulnerability is due to incorrect handling of directory search paths at run time. An attacker…
- risk 0.51cvss 7.8epss 0.00
Uncontrolled search path in the Intel(R) RealSense(TM) D400 Series UWP driver for Windows 10 before version 6.1.160.22 may allow an authenticated user to potentially enable escalation of privilege via local access.
- risk 0.51cvss 7.8epss 0.00
An untrusted search path in AMD Radeon settings Installer may lead to a privilege escalation or unauthorized code execution.
- risk 0.51cvss 7.8epss 0.00
When Octopus Tentacle is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access.
- risk 0.51cvss 7.8epss 0.00
When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access.
- risk 0.51cvss 7.8epss 0.00
SupportAssist Client version 3.8 and 3.9 contains an Untrusted search path vulnerability that allows attackers to load an arbitrary .dll file via .dll planting/hijacking, only by a separate administrative action that is not a default part of the SOSInstallerTool.exe installation…
- risk 0.51cvss 7.8epss 0.00
The OpenSSL component of the Teradici PCoIP Software Client prior to version 21.07.0 was compiled without the no-autoload-config option, which allowed an attacker to elevate to the privileges of the running process via placing a specially crafted dll in a build configuration…
- risk 0.51cvss 7.8epss 0.00
The OpenSSL component of the Teradici PCoIP Standard Agent prior to version 21.07.0 was compiled without the no-autoload-config option, which allowed an attacker to elevate to the privileges of the running process via placing a specially crafted dll in a build configuration…