CWE-427
Uncontrolled Search Path Element
Description
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-38 · CAPEC-471
CVEs mapped to this weakness (1,213)
page 14 of 61| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-48677 | Hig | 0.51 | 7.8 | 0.00 | Dec 12, 2023 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40901, Acronis Cyber Protect Cloud Agent (Windows) before build 39378, Acronis Cyber Protect 16 (Windows) before build… | ||
| CVE-2023-48861 | Hig | 0.51 | 7.8 | 0.00 | Dec 7, 2023 | DLL hijacking vulnerability in TTplayer version 7.0.2, allows local attackers to escalate privileges and execute arbitrary code via urlmon.dll. | ||
| CVE-2023-41613 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | EzViz Studio v2.2.0 is vulnerable to DLL hijacking. | ||
| CVE-2023-45252 | Hig | 0.51 | 7.8 | 0.00 | Dec 1, 2023 | DLL Hijacking vulnerability in Huddly HuddlyCameraService before version 8.0.7, not including version 7.99, due to the installation of the service in a directory that grants write privileges to standard users, allows attackers to manipulate files, execute arbitrary code, and… | ||
| CVE-2023-47454 | Hig | 0.51 | 7.8 | 0.00 | Nov 30, 2023 | An Untrusted search path vulnerability in NetEase CloudMusic 2.10.4 for Windows allows local users to gain escalated privileges through the urlmon.dll file in the current working directory. | ||
| CVE-2023-47453 | Hig | 0.51 | 7.8 | 0.00 | Nov 30, 2023 | An Untrusted search path vulnerability in Sohu Video Player 7.0.15.0 allows local users to gain escalated privileges through the version.dll file in the current working directory. | ||
| CVE-2023-47452 | Hig | 0.51 | 7.8 | 0.01 | Nov 30, 2023 | An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the current working directory. | ||
| CVE-2023-29069 | Hig | 0.51 | 7.8 | 0.00 | Nov 22, 2023 | A maliciously crafted DLL file can be forced to install onto a non-default location, and attacker can overwrite parts of the product with malicious DLLs. These files may then have elevated privileges leading to a Privilege Escalation vulnerability. | ||
| CVE-2023-46814 | Hig | 0.51 | 7.8 | 0.00 | Nov 22, 2023 | A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arbitrary code execution as… | ||
| CVE-2023-6235 | Hig | 0.51 | 7.8 | 0.00 | Nov 21, 2023 | An uncontrolled search path element vulnerability has been found in the Duet Display product, affecting version 2.5.9.1. An attacker could place an arbitrary libusk.dll file in the C:\Users\user\AppData\Local\Microsoft\WindowsApps\ directory, which could lead to the execution… | ||
| CVE-2023-4632 | Hig | 0.51 | 7.8 | 0.00 | Nov 8, 2023 | An uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access to execute code with elevated privileges. | ||
| CVE-2023-5463 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2023 | A vulnerability was found in XINJE XDPPro up to 3.7.17a. It has been rated as critical. Affected by this issue is some unknown functionality in the library cfgmgr32.dll. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The exploit has… | ||
| CVE-2022-4956 | Hig | 0.51 | 7.8 | 0.00 | Sep 30, 2023 | A vulnerability classified as critical has been found in Caphyon Advanced Installer 19.7. This affects an unknown part of the component WinSxS DLL Handler. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The exploit has been disclosed to… | ||
| CVE-2023-39374 | Hig | 0.51 | 7.8 | 0.00 | Sep 3, 2023 | ForeScout NAC SecureConnector version 11.2 - CWE-427: Uncontrolled Search Path Element | ||
| CVE-2023-3078 | Hig | 0.51 | 7.8 | 0.00 | Aug 17, 2023 | An uncontrolled search path vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to execute code with elevated privileges. | ||
| CVE-2023-36344 | Hig | 0.51 | 7.8 | 0.00 | Aug 8, 2023 | An issue in Diebold Nixdorf Vynamic View Console v.5.3.1 and before allows a local attacker to execute arbitrary code via not restricting the search path for required DLLs and not verifying the signature. | ||
| CVE-2021-41544 | Hig | 0.51 | 7.8 | 0.00 | Aug 8, 2023 | A vulnerability has been identified in Siemens Software Center (All versions < V3.0). A DLL Hijacking vulnerability could allow a local attacker to execute code with elevated privileges by placing a malicious DLL in one of the directories on the DLL search path. | ||
| CVE-2022-43703 | Hig | 0.51 | 7.8 | 0.00 | Jul 27, 2023 | An installer that loads or executes files using an unconstrained search path may be vulnerable to substitute files under control of an attacker being loaded or executed instead of the intended files. | ||
| CVE-2023-36853 | Hig | 0.51 | 7.8 | 0.00 | Jul 19, 2023 | In Keysight Geolocation Server v2.4.2 and prior, a low privileged attacker could create a local ZIP file containing a malicious script in any location. The attacker could abuse this to load a DLL with SYSTEM privileges. | ||
| CVE-2023-28929 | Hig | 0.51 | 7.8 | 0.00 | Jun 26, 2023 | Trend Micro Security 2021, 2022, and 2023 (Consumer) are vulnerable to a DLL Hijacking vulnerability which could allow an attacker to use a specific executable file as an execution and/or persistence mechanism which could execute a malicious program each time the executable file… |
- risk 0.51cvss 7.8epss 0.00
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40901, Acronis Cyber Protect Cloud Agent (Windows) before build 39378, Acronis Cyber Protect 16 (Windows) before build…
- risk 0.51cvss 7.8epss 0.00
DLL hijacking vulnerability in TTplayer version 7.0.2, allows local attackers to escalate privileges and execute arbitrary code via urlmon.dll.
- risk 0.51cvss 7.8epss 0.00
EzViz Studio v2.2.0 is vulnerable to DLL hijacking.
- risk 0.51cvss 7.8epss 0.00
DLL Hijacking vulnerability in Huddly HuddlyCameraService before version 8.0.7, not including version 7.99, due to the installation of the service in a directory that grants write privileges to standard users, allows attackers to manipulate files, execute arbitrary code, and…
- risk 0.51cvss 7.8epss 0.00
An Untrusted search path vulnerability in NetEase CloudMusic 2.10.4 for Windows allows local users to gain escalated privileges through the urlmon.dll file in the current working directory.
- risk 0.51cvss 7.8epss 0.00
An Untrusted search path vulnerability in Sohu Video Player 7.0.15.0 allows local users to gain escalated privileges through the version.dll file in the current working directory.
- risk 0.51cvss 7.8epss 0.01
An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the current working directory.
- risk 0.51cvss 7.8epss 0.00
A maliciously crafted DLL file can be forced to install onto a non-default location, and attacker can overwrite parts of the product with malicious DLLs. These files may then have elevated privileges leading to a Privilege Escalation vulnerability.
- risk 0.51cvss 7.8epss 0.00
A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arbitrary code execution as…
- risk 0.51cvss 7.8epss 0.00
An uncontrolled search path element vulnerability has been found in the Duet Display product, affecting version 2.5.9.1. An attacker could place an arbitrary libusk.dll file in the C:\Users\user\AppData\Local\Microsoft\WindowsApps\ directory, which could lead to the execution…
- risk 0.51cvss 7.8epss 0.00
An uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access to execute code with elevated privileges.
- risk 0.51cvss 7.8epss 0.00
A vulnerability was found in XINJE XDPPro up to 3.7.17a. It has been rated as critical. Affected by this issue is some unknown functionality in the library cfgmgr32.dll. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The exploit has…
- risk 0.51cvss 7.8epss 0.00
A vulnerability classified as critical has been found in Caphyon Advanced Installer 19.7. This affects an unknown part of the component WinSxS DLL Handler. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The exploit has been disclosed to…
- risk 0.51cvss 7.8epss 0.00
ForeScout NAC SecureConnector version 11.2 - CWE-427: Uncontrolled Search Path Element
- risk 0.51cvss 7.8epss 0.00
An uncontrolled search path vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to execute code with elevated privileges.
- risk 0.51cvss 7.8epss 0.00
An issue in Diebold Nixdorf Vynamic View Console v.5.3.1 and before allows a local attacker to execute arbitrary code via not restricting the search path for required DLLs and not verifying the signature.
- risk 0.51cvss 7.8epss 0.00
A vulnerability has been identified in Siemens Software Center (All versions < V3.0). A DLL Hijacking vulnerability could allow a local attacker to execute code with elevated privileges by placing a malicious DLL in one of the directories on the DLL search path.
- risk 0.51cvss 7.8epss 0.00
An installer that loads or executes files using an unconstrained search path may be vulnerable to substitute files under control of an attacker being loaded or executed instead of the intended files.
- risk 0.51cvss 7.8epss 0.00
In Keysight Geolocation Server v2.4.2 and prior, a low privileged attacker could create a local ZIP file containing a malicious script in any location. The attacker could abuse this to load a DLL with SYSTEM privileges.
- risk 0.51cvss 7.8epss 0.00
Trend Micro Security 2021, 2022, and 2023 (Consumer) are vulnerable to a DLL Hijacking vulnerability which could allow an attacker to use a specific executable file as an execution and/or persistence mechanism which could execute a malicious program each time the executable file…