VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,213)

page 19 of 61
  • CVE-2021-44198HigNov 29, 2021
    risk 0.51cvss 7.8epss 0.00

    DLL hijacking could lead to local privilege escalation. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035

  • CVE-2021-0082HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path in software installer for Intel(R) PROSet/Wireless WiFi in Windows 10 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-31853HigNov 10, 2021
    risk 0.51cvss 7.8epss 0.00

    DLL Search Order Hijacking Vulnerability in McAfee Drive Encryption (MDE) prior to 7.3.0 HF2 (7.3.0.183) allows local users to execute arbitrary code and escalate privileges via execution from a compromised folder.

  • CVE-2021-38420HigNov 3, 2021
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow an attacker to modify the installation directory and upload malicious files.

  • CVE-2021-38416HigNov 3, 2021
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DIALink versions 1.2.4.0 and prior insecurely loads libraries, which may allow an attacker to use DLL hijacking and takeover the system where the software is installed.

  • CVE-2021-22037HigOct 29, 2021
    risk 0.51cvss 7.8epss 0.00

    Under certain circumstances, when manipulating the Windows registry, InstallBuilder uses the reg.exe system command. The full path to the command is not enforced, which results in a search in the search path until a binary can be identified. This makes the installer/uninstaller…

  • CVE-2021-30359HigOct 22, 2021
    risk 0.51cvss 7.8epss 0.04

    The Harmony Browse and the SandBlast Agent for Browsers installers must have admin privileges to execute some steps during the installation. Because the MS Installer allows regular users to repair their installation, an attacker running an installer before 90.08.7405 can start…

  • CVE-2021-42103HigOct 21, 2021
    risk 0.51cvss 7.8epss 0.00

    An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in…

  • CVE-2021-42102HigOct 21, 2021
    risk 0.51cvss 7.8epss 0.00

    An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service agents could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target…

  • CVE-2021-42101HigOct 21, 2021
    risk 0.51cvss 7.8epss 0.00

    An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in…

  • CVE-2021-28130HigSep 24, 2021
    risk 0.51cvss 7.8epss 0.00

    Dr.Web Firewall 12.5.2.4160 on Windows incorrectly restricts applications signed by Dr.Web. A DLL for a custom payload within a legitimate binary (e.g., frwl_svc.exe) bypasses firewall filters.

  • CVE-2021-26750HigSep 23, 2021
    risk 0.51cvss 7.8epss 0.00

    DLL hijacking in Panda Agent <=1.16.11 in Panda Security, S.L.U. Panda Adaptive Defense 360 <= 8.0.17 allows attacker to escalate privileges via maliciously crafted DLL file.

  • CVE-2021-36216HigSep 8, 2021
    risk 0.51cvss 7.8epss 0.00

    LINE for Windows 6.2.1.2289 and before allows arbitrary code execution via malicious DLL injection.

  • CVE-2021-22775HigSep 2, 2021
    risk 0.51cvss 7.8epss 0.00

    A CWE-427: Uncontrolled Search Path Element vulnerability exists in GP-Pro EX,V4.09.250 and prior, that could cause local code execution with elevated privileges when installing the software.

  • CVE-2021-20793HigAug 26, 2021
    risk 0.51cvss 7.8epss 0.00

    Untrusted search path vulnerability in the installer of Sony Audio USB Driver V1.10 and prior and the installer of HAP Music Transfer Ver.1.3.0 and prior allows an attacker to gain privileges and execute arbitrary code via a Trojan horse DLL in an unspecified directory.

  • CVE-2021-28594HigAug 24, 2021
    risk 0.51cvss 7.8epss 0.03

    Adobe Creative Cloud Desktop Application (installer) version 2.4 (and earlier) is affected by an Uncontrolled Search Path Element vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user.…

  • CVE-2021-28595HigAug 20, 2021
    risk 0.51cvss 7.8epss 0.03

    Adobe Dimension version 3.4 (and earlier) is affected by an Uncontrolled Search Path Element element. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user…

  • CVE-2021-38086HigAug 12, 2021
    risk 0.51cvss 7.8epss 0.00

    Acronis Cyber Protect 15 for Windows prior to build 27009 and Acronis Agent for Windows prior to build 26226 allowed local privilege escalation via DLL hijacking.

  • CVE-2021-38571HigAug 11, 2021
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows DLL hijacking, aka CNVD-C-2021-68000 and CNVD-C-2021-68502.

  • CVE-2021-0160HigAug 11, 2021
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path in some Intel(R) NUC Pro Chassis Element AverMedia Capture Card drivers before version 3.0.64.143 may allow an authenticated user to potentially enable escalation of privilege via local access.