VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,213)

page 12 of 61
  • CVE-2024-7244HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    Panda Security Dome VPN DLL Hijacking Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the…

  • CVE-2024-48605HigOct 22, 2024
    risk 0.51cvss 7.8epss 0.01

    An issue in Helakuru Desktop Application v1.1 allows a local attacker to execute arbitrary code via the lack of proper validation of the wow64log.dll file.

  • CVE-2024-10093HigOct 17, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability, which was classified as critical, was found in VSO ConvertXtoDvd 7.0.0.83. Affected is an unknown function in the library avcodec.dll of the file ConvertXtoDvd.exe. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The…

  • CVE-2024-10068HigOct 17, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in OpenSight Software FlashFXP 5.4.0.3970. It has been classified as critical. Affected is an unknown function in the library libcrypto-1_1.dll of the file FlashFXP.exe. The manipulation leads to uncontrolled search path. An attack has to be approached…

  • CVE-2024-45710HigOct 16, 2024
    risk 0.51cvss 7.8epss 0.00

    SolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This requires a low privilege account and local access to the affected node machine.

  • CVE-2024-9046HigOct 11, 2024
    risk 0.51cvss 7.8epss 0.00

    A DLL hijack vulnerability was reported in Lenovo stARstudio that could allow a local attacker to execute code with elevated privileges.

  • CVE-2024-4132HigOct 11, 2024
    risk 0.51cvss 7.8epss 0.00

    A DLL hijack vulnerability was reported in Lenovo Lock Screen that could allow a local attacker to execute code with elevated privileges.

  • CVE-2024-4131HigOct 11, 2024
    risk 0.51cvss 7.8epss 0.00

    A DLL hijack vulnerability was reported in Lenovo Emulator that could allow a local attacker to execute code with elevated privileges.

  • CVE-2024-4130HigOct 11, 2024
    risk 0.51cvss 7.8epss 0.00

    A DLL hijack vulnerability was reported in Lenovo App Store that could allow a local attacker to execute code with elevated privileges.

  • CVE-2024-4089HigOct 11, 2024
    risk 0.51cvss 7.8epss 0.00

    A DLL hijack vulnerability was reported in Lenovo Super File that could allow a local attacker to execute code with elevated privileges.

  • CVE-2024-33582HigOct 11, 2024
    risk 0.51cvss 7.8epss 0.00

    A DLL hijack vulnerability was reported in Lenovo Service Framework that could allow a local attacker to execute code with elevated privileges.

  • CVE-2024-33581HigOct 11, 2024
    risk 0.51cvss 7.8epss 0.00

    A DLL hijack vulnerability was reported in Lenovo PC Manager AI intelligent scenario that could allow a local attacker to execute code with elevated privileges.

  • CVE-2024-33580HigOct 11, 2024
    risk 0.51cvss 7.8epss 0.00

    A DLL hijack vulnerability was reported in Lenovo Personal Cloud that could allow a local attacker to execute code with elevated privileges.

  • CVE-2024-33579HigOct 11, 2024
    risk 0.51cvss 7.8epss 0.00

    A DLL hijack vulnerability was reported in Lenovo Baiying that could allow a local attacker to execute code with elevated privileges.

  • CVE-2024-33578HigOct 11, 2024
    risk 0.51cvss 7.8epss 0.00

    A DLL hijack vulnerability was reported in Lenovo Leyun that could allow a local attacker to execute code with elevated privileges.

  • CVE-2024-6510HigSep 12, 2024
    risk 0.51cvss 7.8epss 0.00

    Local Privilege Escalation in AVG Internet Security v24 on Windows allows a local unprivileged user to escalate privileges to SYSTEM via COM-Hijacking.

  • CVE-2024-7834HigSep 4, 2024
    risk 0.51cvss 7.8epss 0.00

    A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-writeable folder in SYSTEM context on launch. This allows an attacker with unprivileged access to the system to run arbitrary code with SYSTEM privileges by…

  • CVE-2024-5929HigAug 21, 2024
    risk 0.51cvss 7.8epss 0.00

    VIPRE Advanced Security PMAgent Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Advanced Security. An attacker must first obtain the ability to execute…

  • CVE-2024-7886HigAug 16, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been found in Scooter Software Beyond Compare up to 3.3.5.15075 and classified as critical. Affected by this vulnerability is an unknown functionality in the library 7zxa.dll. The manipulation leads to uncontrolled search path. Attacking locally is a…

  • CVE-2024-7326HigJul 31, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability classified as critical has been found in IObit DualSafe Password Manager 1.4.0.3. This affects an unknown part in the library RTL120.BPL of the component BPL Handler. The manipulation leads to uncontrolled search path. It is possible to launch the attack on the…