VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,213)

page 17 of 61
  • CVE-2022-34901HigJul 18, 2022
    risk 0.51cvss 7.8epss 0.00

    This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to exploit this vulnerability. The…

  • CVE-2022-34900HigJul 18, 2022
    risk 0.51cvss 7.8epss 0.00

    This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.3 (39313) Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific…

  • CVE-2022-29187HigJul 12, 2022
    risk 0.51cvss 7.8epss 0.00

    Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privilege escalation in all platforms. An unsuspecting user could still be affected by the issue reported in CVE-2022-24765,…

  • CVE-2022-33037HigJun 29, 2022
    risk 0.51cvss 7.8epss 0.00

    A binary hijack in Orwell-Dev-Cpp v5.11 allows attackers to execute arbitrary code via a crafted .exe file.

  • CVE-2022-33036HigJun 29, 2022
    risk 0.51cvss 7.8epss 0.00

    A binary hijack in Embarcadero Dev-CPP v6.3 allows attackers to execute arbitrary code via a crafted .exe file.

  • CVE-2022-33035HigJun 29, 2022
    risk 0.51cvss 7.8epss 0.00

    XLPD v7.0.0094 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.

  • CVE-2022-1824HigJun 20, 2022
    risk 0.51cvss 7.9epss 0.00

    An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local attacker to perform a sideloading attack by using a specific file name. This could result in the user gaining elevated permissions and being able to…

  • CVE-2022-24077HigJun 13, 2022
    risk 0.51cvss 7.8epss 0.00

    Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection.

  • CVE-2022-29092HigJun 10, 2022
    risk 0.51cvss 7.8epss 0.00

    Dell SupportAssist Client Consumer versions (3.11.0 and versions prior) and Dell SupportAssist Client Commercial versions (3.2.0 and versions prior) contain a privilege escalation vulnerability. A non-admin user can exploit the vulnerability and gain admin access to the system.

  • CVE-2022-30701HigMay 27, 2022
    risk 0.51cvss 7.8epss 0.00

    An uncontrolled search path element vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to craft a special configuration file to load an untrusted library with escalated privileges on affected installations. Please note: an attacker must…

  • CVE-2022-28394HigMay 27, 2022
    risk 0.51cvss 7.8epss 0.00

    EOL Product CVE - Installer of Trend Micro Password Manager (Consumer) versions 3.7.0.1223 and below provided by Trend Micro Incorporated contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427). Please note that this was…

  • CVE-2022-31467HigMay 23, 2022
    risk 0.51cvss 7.9epss 0.00

    A DLL hijacking vulnerability in the installed for Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, leading to execution of arbitrary code, via the installer not restricting the search path for required DLLs and then not…

  • CVE-2022-30697HigMay 16, 2022
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 3640

  • CVE-2022-30696HigMay 16, 2022
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation due to a DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 3640

  • CVE-2021-20051HigMay 4, 2022
    risk 0.51cvss 7.8epss 0.01

    SonicWall Global VPN Client 4.10.7.1117 installer (32-bit and 64-bit) and earlier versions have a DLL Search Order Hijacking vulnerability in one of the installer components. Successful exploitation via a local attacker could result in command execution in the target system.

  • CVE-2022-24767HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.01

    GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user account.

  • CVE-2022-1098HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DIAEnergie (all versions prior to 1.8.02.004) are vulnerable to a DLL hijacking condition. When combined with the Incorrect Default Permissions vulnerability of 4.2.2 above, this makes it possible for an attacker to escalate privileges

  • CVE-2022-24426HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.00

    Dell Command | Update, Dell Update, and Alienware Update version 4.4.0 contains a Local Privilege Escalation Vulnerability in the Advanced Driver Restore component. A local malicious user could potentially exploit this vulnerability, leading to privilege escalation.

  • CVE-2022-28128HigMar 31, 2022
    risk 0.51cvss 7.8epss 0.00

    Untrusted search path vulnerability in AttacheCase ver.3.6.1.0 and earlier allows an attacker to gain privileges and execute arbitrary code via a Trojan horse DLL in an unspecified directory.

  • CVE-2022-25348HigMar 31, 2022
    risk 0.51cvss 7.8epss 0.00

    Untrusted search path vulnerability in AttacheCase ver.4.0.2.7 and earlier allows an attacker to gain privileges and execute arbitrary code via a Trojan horse DLL in an unspecified directory.