VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,233)

page 13 of 62
  • CVE-2024-4132HigOct 11, 2024
    risk 0.51cvss 7.8epss 0.00

    A DLL hijack vulnerability was reported in Lenovo Lock Screen that could allow a local attacker to execute code with elevated privileges.

  • CVE-2024-4131HigOct 11, 2024
    risk 0.51cvss 7.8epss 0.00

    A DLL hijack vulnerability was reported in Lenovo Emulator that could allow a local attacker to execute code with elevated privileges.

  • CVE-2024-4130HigOct 11, 2024
    risk 0.51cvss 7.8epss 0.00

    A DLL hijack vulnerability was reported in Lenovo App Store that could allow a local attacker to execute code with elevated privileges.

  • CVE-2024-4089HigOct 11, 2024
    risk 0.51cvss 7.8epss 0.00

    A DLL hijack vulnerability was reported in Lenovo Super File that could allow a local attacker to execute code with elevated privileges.

  • CVE-2024-33582HigOct 11, 2024
    risk 0.51cvss 7.8epss 0.00

    A DLL hijack vulnerability was reported in Lenovo Service Framework that could allow a local attacker to execute code with elevated privileges.

  • CVE-2024-33581HigOct 11, 2024
    risk 0.51cvss 7.8epss 0.00

    A DLL hijack vulnerability was reported in Lenovo PC Manager AI intelligent scenario that could allow a local attacker to execute code with elevated privileges.

  • CVE-2024-33580HigOct 11, 2024
    risk 0.51cvss 7.8epss 0.00

    A DLL hijack vulnerability was reported in Lenovo Personal Cloud that could allow a local attacker to execute code with elevated privileges.

  • CVE-2024-33579HigOct 11, 2024
    risk 0.51cvss 7.8epss 0.00

    A DLL hijack vulnerability was reported in Lenovo Baiying that could allow a local attacker to execute code with elevated privileges.

  • CVE-2024-33578HigOct 11, 2024
    risk 0.51cvss 7.8epss 0.00

    A DLL hijack vulnerability was reported in Lenovo Leyun that could allow a local attacker to execute code with elevated privileges.

  • CVE-2024-6510HigSep 12, 2024
    risk 0.51cvss 7.8epss 0.00

    Local Privilege Escalation in AVG Internet Security v24 on Windows allows a local unprivileged user to escalate privileges to SYSTEM via COM-Hijacking.

  • CVE-2024-7834HigSep 4, 2024
    risk 0.51cvss 7.8epss 0.00

    A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-writeable folder in SYSTEM context on launch. This allows an attacker with unprivileged access to the system to run arbitrary code with SYSTEM privileges by…

  • CVE-2024-5929HigAug 21, 2024
    risk 0.51cvss 7.8epss 0.00

    VIPRE Advanced Security PMAgent Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Advanced Security. An attacker must first obtain the ability to execute…

  • CVE-2024-7886HigAug 16, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been found in Scooter Software Beyond Compare up to 3.3.5.15075 and classified as critical. Affected by this vulnerability is an unknown functionality in the library 7zxa.dll. The manipulation leads to uncontrolled search path. Attacking locally is a…

  • CVE-2024-7326HigJul 31, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability classified as critical has been found in IObit DualSafe Password Manager 1.4.0.3. This affects an unknown part in the library RTL120.BPL of the component BPL Handler. The manipulation leads to uncontrolled search path. It is possible to launch the attack on the…

  • CVE-2024-7325HigJul 31, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in IObit Driver Booster 11.0.0.0. It has been rated as critical. Affected by this issue is some unknown functionality in the library VCL120.BPL of the component BPL Handler. The manipulation leads to uncontrolled search path. Attacking locally is a…

  • CVE-2024-7324HigJul 31, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in IObit iTop Data Recovery Pro 4.4.0.687. It has been declared as critical. Affected by this vulnerability is an unknown functionality in the library madbasic_.bpl of the component BPL Handler. The manipulation leads to uncontrolled search path. Local…

  • CVE-2024-37127HigJul 31, 2024
    risk 0.51cvss 7.8epss 0.00

    Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL or symbolic link exploitation, leading to arbitrary code execution and…

  • CVE-2024-5509HigJun 6, 2024
    risk 0.51cvss 7.8epss 0.01

    Luxion KeyShot BIP File Parsing Uncontrolled Search Path Element Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in…

  • CVE-2024-5292HigMay 23, 2024
    risk 0.51cvss 7.8epss 0.01

    D-Link Network Assistant Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of D-Link Network Assistant. An attacker must first obtain the ability to execute…

  • CVE-2024-20366HigMay 15, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in the Tail-f High Availability Cluster Communications (HCC) function pack of Cisco Crosswork Network Services Orchestrator (NSO) could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability exists…