VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,233)

page 15 of 62
  • CVE-2023-47452HigNov 30, 2023
    risk 0.51cvss 7.8epss 0.01

    An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the current working directory.

  • CVE-2023-29069HigNov 22, 2023
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DLL file can be forced to install onto a non-default location, and attacker can overwrite parts of the product with malicious DLLs. These files may then have elevated privileges leading to a Privilege Escalation vulnerability.

  • CVE-2023-46814HigNov 22, 2023
    risk 0.51cvss 7.8epss 0.00

    A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arbitrary code execution as…

  • CVE-2023-6235HigNov 21, 2023
    risk 0.51cvss 7.8epss 0.00

    An uncontrolled search path element vulnerability has been found in the Duet Display product, affecting version 2.5.9.1. An attacker could place an arbitrary libusk.dll file in the C:\Users\user\AppData\Local\Microsoft\WindowsApps\ directory, which could lead to the execution…

  • CVE-2023-4632HigNov 8, 2023
    risk 0.51cvss 7.8epss 0.00

    An uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access to execute code with elevated privileges.

  • CVE-2023-5463HigOct 9, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in XINJE XDPPro up to 3.7.17a. It has been rated as critical. Affected by this issue is some unknown functionality in the library cfgmgr32.dll. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The exploit has…

  • CVE-2022-4956HigSep 30, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability classified as critical has been found in Caphyon Advanced Installer 19.7. This affects an unknown part of the component WinSxS DLL Handler. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The exploit has been disclosed to…

  • CVE-2023-39374HigSep 3, 2023
    risk 0.51cvss 7.8epss 0.00

    ForeScout NAC SecureConnector version 11.2 - CWE-427: Uncontrolled Search Path Element

  • CVE-2023-3078HigAug 17, 2023
    risk 0.51cvss 7.8epss 0.00

    An uncontrolled search path vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to execute code with elevated privileges.

  • CVE-2023-36344HigAug 8, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue in Diebold Nixdorf Vynamic View Console v.5.3.1 and before allows a local attacker to execute arbitrary code via not restricting the search path for required DLLs and not verifying the signature.

  • CVE-2021-41544HigAug 8, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Siemens Software Center (All versions < V3.0). A DLL Hijacking vulnerability could allow a local attacker to execute code with elevated privileges by placing a malicious DLL in one of the directories on the DLL search path.

  • CVE-2022-43703HigJul 27, 2023
    risk 0.51cvss 7.8epss 0.00

    An installer that loads or executes files using an unconstrained search path may be vulnerable to substitute files under control of an attacker being loaded or executed instead of the intended files.

  • CVE-2023-36853HigJul 19, 2023
    risk 0.51cvss 7.8epss 0.00

    ​In Keysight Geolocation Server v2.4.2 and prior, a low privileged attacker could create a local ZIP file containing a malicious script in any location. The attacker could abuse this to load a DLL with SYSTEM privileges.

  • CVE-2023-28929HigJun 26, 2023
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Security 2021, 2022, and 2023 (Consumer) are vulnerable to a DLL Hijacking vulnerability which could allow an attacker to use a specific executable file as an execution and/or persistence mechanism which could execute a malicious program each time the executable file…

  • CVE-2023-27908HigJun 23, 2023
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DLL file can be forced to write beyond allocated boundaries in the Autodesk installer when parsing the DLL files and could lead to a Privilege Escalation vulnerability.

  • CVE-2023-25005HigMay 12, 2023
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DLL file can be forced to read beyond allocated boundaries in Autodesk InfraWorks 2023, and 2021 when parsing the DLL files could lead to a resource injection vulnerability.

  • CVE-2023-25428HigMay 12, 2023
    risk 0.51cvss 7.8epss 0.00

    A DLL Hijacking issue discovered in Soft-o Free Password Manager 1.1.20 allows attackers to create arbitrary DLLs leading to code execution.

  • CVE-2023-30237HigMay 9, 2023
    risk 0.51cvss 7.8epss 0.00

    CyberGhostVPN Windows Client before v8.3.10.10015 was discovered to contain a DLL injection vulnerability via the component Dashboard.exe.

  • CVE-2023-2355HigApr 27, 2023
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation due to a DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 3900.

  • CVE-2022-48222HigApr 4, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During SDK installation, certutil.exe is called by the Acuant installer to install certificates. This window is not hidden, and is running with elevated privileges. A standard user can break out of this window,…