VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,213)

page 18 of 61
  • CVE-2022-22996HigMar 30, 2022
    risk 0.51cvss 7.8epss 0.00

    The G-RAID 4/8 Software Utility setups for Windows were affected by a DLL hijacking vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the system user.

  • CVE-2022-26511HigMar 17, 2022
    risk 0.51cvss 7.8epss 0.01

    WPS Presentation 11.8.0.5745 insecurely load d3dx9_41.dll when opening .pps files('current directory type' DLL loading).

  • CVE-2022-26081HigMar 17, 2022
    risk 0.51cvss 7.8epss 0.01

    The installer of WPS Office Version 10.8.0.5745 insecurely load shcore.dll, allowing an attacker to execute arbitrary code with the privilege of the user invoking the installer.

  • CVE-2022-25969HigMar 17, 2022
    risk 0.51cvss 7.8epss 0.01

    The installer of WPS Office Version 10.8.0.6186 insecurely load VERSION.DLL (or some other DLLs), allowing an attacker to execute arbitrary code with the privilege of the user invoking the installer.

  • CVE-2022-23401HigMar 11, 2022
    risk 0.51cvss 7.8epss 0.00

    The following Yokogawa Electric products contain insecure DLL loading issues. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00.

  • CVE-2022-26337HigMar 8, 2022
    risk 0.51cvss 7.8epss 0.01

    Trend Micro Password Manager (Consumer) installer version 5.0.0.1262 and below is vulnerable to an Uncontrolled Search Path Element vulnerability that could allow an attacker to use a specially crafted file to exploit the vulnerability and escalate local privileges on the…

  • CVE-2021-43940HigFeb 15, 2022
    risk 0.51cvss 7.8epss 0.00

    Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer. This vulnerability only affects installations of Confluence…

  • CVE-2022-23410HigFeb 14, 2022
    risk 0.51cvss 7.8epss 0.00

    AXIS IP Utility before 4.18.0 allows for remote code execution and local privilege escalation by the means of DLL hijacking. IPUtility.exe would attempt to load DLLs from its current working directory which could allow for remote code execution if a compromised DLL would be…

  • CVE-2022-23853HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.01

    The LSP (Language Server Protocol) plugin in KDE Kate before 21.12.2 and KTextEditor before 5.91.0 tries to execute the associated LSP server binary when opening a file of a given type. If this binary is absent from the PATH, it will try running the LSP server binary in the…

  • CVE-2022-0483HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53

  • CVE-2022-22528HigFeb 9, 2022
    risk 0.51cvss 7.8epss 0.00

    SAP Adaptive Server Enterprise (ASE) - version 16.0, installation makes an entry in the system PATH environment variable in Windows platform which, under certain conditions, allows a Standard User to execute malicious Windows binaries which may lead to privilege escalation on…

  • CVE-2021-33101HigFeb 9, 2022
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path in the Intel(R) GPA software before version 21.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-12891HigFeb 4, 2022
    risk 0.51cvss 7.8epss 0.00

    AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop its malicious DLL file in any location which is in path environment variable.

  • CVE-2022-0166HigJan 19, 2022
    risk 0.51cvss 7.8epss 0.03

    A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5. McAfee Agent uses openssl.cnf during the build process to specify the OPENSSLDIR variable as a subdirectory within the installation directory. A low privilege user could have created subdirectories and…

  • CVE-2022-0015HigJan 12, 2022
    risk 0.51cvss 7.8epss 0.00

    A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authenticated local user to execute programs with elevated privileges. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12; Cortex…

  • CVE-2021-30360HigJan 10, 2022
    risk 0.51cvss 7.8epss 0.01

    Users have access to the directory where the installation repair occurs. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted EXE in the repair folder which runs with the Check Point Remote…

  • CVE-2021-4007HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.00

    Rapid7 Insight Agent, versions 3.0.1 to 3.1.2.34, suffer from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when Insight Agent versions 3.0.1 to 3.1.2.34 start, the Python interpreter attempts to load python3.dll at "C:\DLLs\python3.dll,"…

  • CVE-2021-20047HigDec 8, 2021
    risk 0.51cvss 7.8epss 0.01

    SonicWall Global VPN client version 4.10.6 (32-bit and 64-bit) and earlier have a DLL Search Order Hijacking vulnerability. Successful exploitation via a local attacker could result in remote code execution in the target system.

  • CVE-2021-43037HigDec 6, 2021
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Unitrends Windows agent was vulnerable to DLL injection and binary planting due to insecure default permissions. This allowed privilege escalation from an unprivileged user to SYSTEM.

  • CVE-2021-32592HigDec 1, 2021
    risk 0.51cvss 7.8epss 0.00

    An unsafe search path vulnerability in FortiClientWindows 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x and FortiClientEMS 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x may allow an attacker to perform a DLL Hijack attack on affected devices via a malicious OpenSSL engine library in the search…