VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,233)

page 21 of 62
  • CVE-2021-3042HigJul 15, 2021
    risk 0.51cvss 7.8epss 0.00

    A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated local Windows user to execute programs with SYSTEM privileges. Exploiting this vulnerability requires the user to have file…

  • CVE-2020-29157HigJul 14, 2021
    risk 0.51cvss 7.8epss 0.00

    An issue in RAONWIZ K Editor v2018.0.0.10 allows attackers to perform a DLL hijacking attack when the service or system is restarted.

  • CVE-2021-22000HigJul 13, 2021
    risk 0.51cvss 7.8epss 0.01

    VMware Thinapp version 5.x prior to 5.2.10 contain a DLL hijacking vulnerability due to insecure loading of DLLs. A malicious actor with non-administrative privileges may exploit this vulnerability to elevate privileges to administrator level on the Windows operating system…

  • CVE-2021-3613HigJul 2, 2021
    risk 0.51cvss 7.8epss 0.01

    OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (OpenVPNConnect.exe).

  • CVE-2021-3606HigJul 2, 2021
    risk 0.51cvss 7.8epss 0.00

    OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (openvpn.exe).

  • CVE-2021-29949HigJun 24, 2021
    risk 0.51cvss 7.8epss 0.00

    When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filename that isn't distributed by Thunderbird. If a computer has already been infected with a malicious library of the alternative filename, and…

  • CVE-2021-21999HigJun 23, 2021
    risk 0.51cvss 7.8epss 0.01

    VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App Volumes (2.x prior to 2.18.10 and 4 prior to 2103) contain a local privilege escalation vulnerability. An attacker with normal access to a virtual machine may…

  • CVE-2021-34803HigJun 16, 2021
    risk 0.51cvss 7.8epss 0.00

    TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations.

  • CVE-2021-23023HigJun 10, 2021
    risk 0.51cvss 7.8epss 0.00

    On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, a DLL hijacking issue exists in cachecleaner.dll included in the BIG-IP Edge Client Windows Installer. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2021-3041HigJun 10, 2021
    risk 0.51cvss 7.8epss 0.00

    A local privilege escalation vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated local Windows user to execute programs with SYSTEM privileges. This requires the user to have the privilege to create files in the…

  • CVE-2021-0104HigJun 9, 2021
    risk 0.51cvss 7.8epss 0.01

    Uncontrolled search path element in the installer for the Intel(R) Rapid Storage Technology software, before versions 17.9.0.34, 18.0.0.640 and 18.1.0.24, may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-0057HigJun 9, 2021
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path in the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2019-4588HigMay 26, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to execute arbitrary code and conduct DLL hijacking attacks.

  • CVE-2021-20726HigMay 24, 2021
    risk 0.51cvss 7.8epss 0.00

    Untrusted search path vulnerability in The Installer of Overwolf 2.168.0.n and earlier allows an attacker to gain privileges and execute arbitrary code with the privilege of the user invoking the installer via a Trojan horse DLL in an unspecified directory.

  • CVE-2021-20722HigMay 24, 2021
    risk 0.51cvss 7.8epss 0.00

    Untrusted search path vulnerability in the installers of ScanSnap Manager prior to versions V7.0L20 and the Software Download Installer prior to WinSSInst2JP.exe and WinSSInst2iX1500JP.exe allows an attacker to gain privileges and execute arbitrary code with the privilege of the…

  • CVE-2021-3423HigMay 18, 2021
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled Search Path Element vulnerability in the openssl component as used in Bitdefender GravityZone Business Security allows an attacker to load a third party DLL to elevate privileges. This issue affects Bitdefender GravityZone Business Security versions prior to…

  • CVE-2020-24755HigMay 17, 2021
    risk 0.51cvss 7.8epss 0.01

    In Ubiquiti UniFi Video v3.10.13, when the executable starts, its first library validation is in the current directory. This allows the impersonation and modification of the library to execute code on the system. This was tested in (Windows 7 x64/Windows 10 x64).

  • CVE-2021-25694HigMay 13, 2021
    risk 0.51cvss 7.8epss 0.00

    Teradici PCoIP Graphics Agent for Windows prior to 21.03 does not validate NVENC.dll. An attacker could replace the .dll and redirect pixels elsewhere.

  • CVE-2021-3464HigApr 27, 2021
    risk 0.51cvss 7.8epss 0.00

    A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow privilege escalation.

  • CVE-2021-28098HigApr 14, 2021
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Forescout CounterACT before 8.1.4. A local privilege escalation vulnerability is present in the logging function. SecureConnector runs with administrative privileges and writes logs entries to a file in %PROGRAMDATA%\ForeScout SecureConnector\ that has…