VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,213)

page 23 of 61
  • CVE-2020-12320HigNov 12, 2020
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path in Intel(R) SCS Add-on for Microsoft* SCCM before version 2.1.10 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-13771HigNov 12, 2020
    risk 0.51cvss 7.8epss 0.01

    Various components in Ivanti Endpoint Manager through 2020.1.1 rely on Windows search order when loading a (nonexistent) library file, allowing (under certain conditions) one to gain code execution (and elevation of privileges to the level of privilege held by the vulnerable…

  • CVE-2020-5992HigNov 11, 2020
    risk 0.51cvss 7.8epss 0.00

    NVIDIA GeForce NOW application software on Windows, all versions prior to 2.0.25.119, contains a vulnerability in its open-source software dependency in which the OpenSSL library is vulnerable to binary planting attacks by a local user, which may lead to code execution or…

  • CVE-2020-25174HigNov 6, 2020
    risk 0.51cvss 7.8epss 0.00

    A DLL hijacking vulnerability in the B. Braun OnlineSuite Version AP 3.0 and earlier allows local attackers to execute code on the system as a high privileged user.

  • CVE-2020-27708HigNov 2, 2020
    risk 0.51cvss 7.8epss 0.01

    A vulnerability exists in the Origin Client that could allow a non-Administrative user to elevate their access to either Administrator or System. Once the user has obtained elevated access, they may be able to take control of the system and perform actions otherwise reserved for…

  • CVE-2019-19115HigOct 8, 2020
    risk 0.51cvss 7.8epss 0.01

    An escalation of privilege vulnerability in Nahimic APO Software Component Driver 1.4.2, 1.5.0, 1.5.1, 1.6.1 and 1.6.2 allows an attacker to execute code with SYSTEM privileges.

  • CVE-2020-3535HigOct 8, 2020
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in the loading mechanism of specific DLLs in the Cisco Webex Teams client for Windows could allow an authenticated, local attacker to load a malicious library. To exploit this vulnerability, the attacker needs valid credentials on the Windows system. The…

  • CVE-2020-26538HigOct 2, 2020
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Foxit Reader and PhantomPDF before 10.1. It allows attackers to execute arbitrary code via a Trojan horse taskkill.exe in the current working directory.

  • CVE-2020-6654HigSep 30, 2020
    risk 0.51cvss 7.8epss 0.00

    A DLL Hijacking vulnerability in Eaton's 9000x Programming and Configuration Software v 2.0.38 and prior allows an attacker to execute arbitrary code by replacing the required DLLs with malicious DLLs when the software try to load vci11un6.DLL and cinpl.DLL.

  • CVE-2020-3979HigSep 18, 2020
    risk 0.51cvss 7.8epss 0.00

    InstallBuilder for Qt Windows (versions prior to 20.7.0) installers look for plugins at a predictable location at initialization time, writable by non-admin users. While those plugins are not required, they are loaded if present, which could allow an attacker to plant a…

  • CVE-2020-7312HigSep 10, 2020
    risk 0.51cvss 7.8epss 0.00

    DLL Search Order Hijacking Vulnerability in the installer in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to execute arbitrary code and escalate privileges via execution from a compromised folder.

  • CVE-2020-24162HigSep 3, 2020
    risk 0.51cvss 7.8epss 0.00

    The Shenzhen Tencent app 5.8.2.5300 for PC platforms (from Tencent App Center) has a DLL hijacking vulnerability. Attackers can use this vulnerability to execute malicious code.

  • CVE-2020-24161HigSep 3, 2020
    risk 0.51cvss 7.8epss 0.00

    Guangzhou NetEase Mail Master 4.14.1.1004 on Windows has a DLL hijacking vulnerability. Attackers can use this vulnerability to execute malicious code.

  • CVE-2020-24160HigSep 3, 2020
    risk 0.51cvss 7.8epss 0.00

    Shenzhen Tencent TIM Windows client 3.0.0.21315 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious code.

  • CVE-2020-24159HigSep 3, 2020
    risk 0.51cvss 7.8epss 0.00

    NetEase Youdao Dictionary has a DLL hijacking vulnerability, which can be exploited by attackers to gain server permissions. This affects Guangzhou NetEase Youdao Dictionary 8.9.2.0.

  • CVE-2020-24158HigSep 3, 2020
    risk 0.51cvss 7.8epss 0.00

    360 Speed Browser 12.0.1247.0 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious code. It is a dual-core browser owned by Beijing Qihoo Technology.

  • CVE-2020-25045HigSep 2, 2020
    risk 0.51cvss 7.8epss 0.00

    Installers of Kaspersky Security Center and Kaspersky Security Center Web Console prior to 12 & prior to 12 Patch A were vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges in the system.

  • CVE-2020-9724HigAug 19, 2020
    risk 0.51cvss 7.8epss 0.03

    Adobe Lightroom versions 9.2.0.10 and earlier have an insecure library loading vulnerability. Successful exploitation could lead to privilege escalation.

  • CVE-2020-9767HigAug 14, 2020
    risk 0.51cvss 7.8epss 0.01

    A vulnerability related to Dynamic-link Library (“DLL”) loading in the Zoom Sharing Service would allow an attacker who had local access to a machine on which the service was running with elevated privileges to elevate their system privileges as well through use of a…

  • CVE-2020-8687HigAug 13, 2020
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path in the installer for Intel(R) RSTe Software RAID Driver for the Intel(R) Server Board M10JNP2SB before version 4.7.0.1119 may allow an authenticated user to potentially enable escalation of privilege via local access.