VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,233)

page 14 of 62
  • CVE-2023-44437HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Ashlar-Vellum Cobalt Uncontrolled Search Path Element Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that…

  • CVE-2023-27362HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    3CX Uncontrolled Search Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of 3CX. An attacker must first obtain the ability to execute low-privileged code on the target system in order to…

  • CVE-2024-28099HigApr 15, 2024
    risk 0.51cvss 7.8epss 0.00

    VT STUDIO Ver.8.32 and earlier contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privileges of the running application.

  • CVE-2024-29734HigApr 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path element issue exists in SonicDICOM Media Viewer 2.3.2 and earlier, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privileges of the running application.

  • CVE-2024-28131HigMar 26, 2024
    risk 0.51cvss 7.8epss 0.00

    EasyRange Ver 1.41 contains an issue with the executable file search path when displaying an extracted file on Explorer, which may lead to loading an executable file resides in the same folder where the extracted file is placed. If this vulnerability is exploited, arbitrary code…

  • CVE-2023-42920HigMar 19, 2024
    risk 0.51cvss 7.8epss 0.00

    Claris International has fixed a dylib hijacking vulnerability in the FileMaker Pro.app and Claris Pro.app versions on macOS.

  • CVE-2024-22167HigMar 13, 2024
    risk 0.51cvss 7.9epss 0.00

    A potential DLL hijacking vulnerability in the SanDisk PrivateAccess application for Windows that could lead to arbitrary code execution in the context of the system user. This vulnerability is only exploitable locally if an attacker has access to a copy of the user's vault or…

  • CVE-2024-1595HigFeb 29, 2024
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics CNCSoft-B DOPSoft prior to v4.0.0.82 insecurely loads libraries, which may allow an attacker to use DLL hijacking and take over the system where the software is installed.

  • CVE-2024-23940HigJan 29, 2024
    risk 0.51cvss 7.8epss 0.01

    Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and below is vulnerable to a DLL hijacking/proxying vulnerability, which if exploited could allow an attacker to impersonate and modify a library to execute code on…

  • CVE-2023-51711HigJan 24, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Regify Regipay Client for Windows version 4.5.1.0 allows DLL hijacking: a user can trigger the execution of arbitrary code every time the product is executed.

  • CVE-2023-32272HigJan 19, 2024
    risk 0.51cvss 7.9epss 0.00

    Uncontrolled search path in some Intel NUC Pro Software Suite Configuration Tool software installers before version 3.0.0.6 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2023-29445HigJan 10, 2024
    risk 0.51cvss 7.8epss 0.00

    An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM.

  • CVE-2023-6338HigJan 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path vulnerabilities were reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to execute code with elevated privileges.

  • CVE-2020-28369HigDec 12, 2023
    risk 0.51cvss 7.8epss 0.00

    In BeyondTrust Privilege Management for Windows (aka PMfW) through 5.7, a SYSTEM installation causes Cryptbase.dll to be loaded from the user-writable location %WINDIR%\Temp.

  • CVE-2023-48677HigDec 12, 2023
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40901, Acronis Cyber Protect Cloud Agent (Windows) before build 39378, Acronis Cyber Protect 16 (Windows) before build…

  • CVE-2023-48861HigDec 7, 2023
    risk 0.51cvss 7.8epss 0.00

    DLL hijacking vulnerability in TTplayer version 7.0.2, allows local attackers to escalate privileges and execute arbitrary code via urlmon.dll.

  • CVE-2023-41613HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    EzViz Studio v2.2.0 is vulnerable to DLL hijacking.

  • CVE-2023-45252HigDec 1, 2023
    risk 0.51cvss 7.8epss 0.00

    DLL Hijacking vulnerability in Huddly HuddlyCameraService before version 8.0.7, not including version 7.99, due to the installation of the service in a directory that grants write privileges to standard users, allows attackers to manipulate files, execute arbitrary code, and…

  • CVE-2023-47454HigNov 30, 2023
    risk 0.51cvss 7.8epss 0.00

    An Untrusted search path vulnerability in NetEase CloudMusic 2.10.4 for Windows allows local users to gain escalated privileges through the urlmon.dll file in the current working directory.

  • CVE-2023-47453HigNov 30, 2023
    risk 0.51cvss 7.8epss 0.00

    An Untrusted search path vulnerability in Sohu Video Player 7.0.15.0 allows local users to gain escalated privileges through the version.dll file in the current working directory.