VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,213)

page 16 of 61
  • CVE-2022-42945HigDec 19, 2022
    risk 0.51cvss 7.8epss 0.00

    DWG TrueViewTM 2023 version has a DLL Search Order Hijacking vulnerability. Successful exploitation by a malicious attacker could result in remote code execution on the target system.

  • CVE-2022-43722HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software does not properly secure a folder containing library files. This could allow an attacker to place a custom malicious DLL in this folder which is then run with SYSTEM rights when a…

  • CVE-2022-38395HigDec 12, 2022
    risk 0.51cvss 7.8epss 0.03

    HP Support Assistant uses HP Performance Tune-up as a diagnostic tool. HP Support Assistant uses Fusion to launch HP Performance Tune-up. It is possible for an attacker to exploit the DLL hijacking vulnerability and elevate privileges when Fusion launches the HP Performance…

  • CVE-2022-43751HigNov 23, 2022
    risk 0.51cvss 7.8epss 0.00

    McAfee Total Protection prior to version 16.0.49 contains an uncontrolled search path element vulnerability due to the use of a variable pointing to a subdirectory that may be controllable by an unprivileged user. This may have allowed the unprivileged user to execute arbitrary…

  • CVE-2022-45422HigNov 21, 2022
    risk 0.51cvss 7.8epss 0.00

    When LG SmartShare is installed, local privilege escalation is possible through DLL Hijacking attack. The LG ID is LVE-HOT-220005.

  • CVE-2022-43310HigNov 9, 2022
    risk 0.51cvss 7.8epss 0.02

    An Uncontrolled Search Path Element in Foxit Software released Foxit Reader v11.2.118.51569 allows attackers to escalate privileges when searching for DLL libraries without specifying an absolute path.

  • CVE-2022-41796HigOct 24, 2022
    risk 0.51cvss 7.8epss 0.00

    Untrusted search path vulnerability in the installer of Content Transfer (for Windows) Ver.1.3 and prior allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2022-38633HigSep 13, 2022
    risk 0.51cvss 7.8epss 0.00

    Genymotion Desktop v3.2.1 was discovered to contain a DLL hijacking vulnerability which allows attackers to escalate privileges and execute arbitrary code via a crafted binary.

  • CVE-2022-34101HigSep 13, 2022
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can place a malicious DLL in a certain path to execute code and preform a privilege escalation attack.

  • CVE-2022-36271HigSep 7, 2022
    risk 0.51cvss 7.8epss 0.01

    Outbyte PC Repair Installation File 1.7.112.7856 is vulnerable to Dll Hijacking. iertutil.dll is missing so an attacker can use a malicious dll with same name and can get admin privileges.

  • CVE-2022-2006HigAug 31, 2022
    risk 0.51cvss 7.8epss 0.00

    AutomationDirect DirectLOGIC has a DLL vulnerability in the install directory that may allow an attacker to execute code during the installation process. This issue affects: AutomationDirect C-more EA9 EA9-T6CL versions prior to 6.73; EA9-T6CL-R versions prior to 6.73; EA9-T7CL…

  • CVE-2022-28696HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path in the Intel(R) Distribution for Python before version 2022.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-26374HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path in the installation binaries for Intel(R) SEAPI all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-25999HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path element in the Intel(R) Enpirion(R) Digital Power Configurator GUI software, all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-25841HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path elements in the Intel(R) Datacenter Group Event Android application, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-21807HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path elements in the Intel(R) VTune(TM) Profiler software before version 2022.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-2334HigAug 17, 2022
    risk 0.51cvss 7.2epss 0.12

    The application searches for a library dll that is not found. If an attacker can place a dll with this name, then the attacker can leverage it to execute arbitrary code on the targeted Softing Secure Integration Server V1.22.

  • CVE-2022-34235HigAug 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Adobe Premiere Elements version 2020v20 (and earlier) is affected by an Uncontrolled Search Path Element which could lead to Privilege Escalation. An attacker could leverage this vulnerability to obtain admin using an existing low-privileged user. Exploitation of this issue does…

  • CVE-2022-36415HigJul 23, 2022
    risk 0.51cvss 7.8epss 0.00

    A DLL hijacking vulnerability exists in the uninstaller in Scooter Beyond Compare 1.8a through 4.4.2 before 4.4.3 when installed via the EXE installer. The uninstaller attempts to load DLLs out of a Windows Temp folder. If a standard user places malicious DLLs in the…

  • CVE-2022-34902HigJul 18, 2022
    risk 0.51cvss 7.8epss 0.00

    This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific…