VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,233)

page 23 of 62
  • CVE-2020-35145HigJan 29, 2021
    risk 0.51cvss 7.8epss 0.01

    Acronis True Image for Windows prior to 2021 Update 3 allowed local privilege escalation due to a DLL hijacking vulnerability in multiple components, aka an Untrusted Search Path issue.

  • CVE-2021-25247HigJan 27, 2021
    risk 0.51cvss 7.8epss 0.01

    A DLL hijacking vulnerability Trend Micro HouseCall for Home Networks version 5.3.1063 and below could allow an attacker to use a malicious DLL to escalate privileges and perform arbitrary code execution. An attacker must already have user privileges on the machine to exploit…

  • CVE-2021-1280HigJan 20, 2021
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in the loading mechanism of specific DLLs of Cisco Advanced Malware Protection (AMP) for Endpoints for Windows and Immunet for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker…

  • CVE-2021-1237HigJan 13, 2021
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in the Network Access Manager and Web Security Agent components of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL injection attack. To exploit this vulnerability, the attacker would need to have…

  • CVE-2021-20616HigJan 13, 2021
    risk 0.51cvss 7.8epss 0.00

    Untrusted search path vulnerability in the installer of SKYSEA Client View Ver.1.020.05b to Ver.16.001.01g allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2020-26050HigJan 12, 2021
    risk 0.51cvss 7.8epss 0.01

    SaferVPN for Windows Ver 5.0.3.3 through 5.0.4.15 could allow local privilege escalation from low privileged users to SYSTEM via a crafted openssl configuration file. This issue is similar to CVE-2019-12572.

  • CVE-2020-35483HigJan 11, 2021
    risk 0.51cvss 7.8epss 0.00

    AnyDesk before 6.1.0 on Windows, when run in portable mode on a system where the attacker has write access to the application directory, allows this attacker to compromise a local user account via a read-only setting for a Trojan horse gcapi.dll file.

  • CVE-2020-5681HigDec 24, 2020
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in self-extracting files created by EpsonNet SetupManager versions 2.2.14 and earlier, and Offirio SynergyWare PrintDirector versions 1.6x/1.6y and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified…

  • CVE-2020-29654HigDec 12, 2020
    risk 0.51cvss 7.8epss 0.00

    Western Digital Dashboard before 3.2.2.9 allows DLL Hijacking that leads to compromise of the SYSTEM account.

  • CVE-2020-2049HigDec 9, 2020
    risk 0.51cvss 7.8epss 0.00

    A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that allows an authenticated local Windows user to execute programs with SYSTEM privileges. This requires the user to have the privilege to create files in the…

  • CVE-2020-28950HigDec 4, 2020
    risk 0.51cvss 7.8epss 0.00

    The installer of Kaspersky Anti-Ransomware Tool (KART) prior to KART 4.0 Patch C was vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges during installation process.

  • CVE-2020-6021HigDec 3, 2020
    risk 0.51cvss 7.8epss 0.00

    Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes place. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a…

  • CVE-2020-5674HigNov 24, 2020
    risk 0.51cvss 7.8epss 0.00

    Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2020-12329HigNov 12, 2020
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path in the Intel(R) VTune(TM) Profiler before version 2020 Update 1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-12320HigNov 12, 2020
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path in Intel(R) SCS Add-on for Microsoft* SCCM before version 2.1.10 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-13771HigNov 12, 2020
    risk 0.51cvss 7.8epss 0.01

    Various components in Ivanti Endpoint Manager through 2020.1.1 rely on Windows search order when loading a (nonexistent) library file, allowing (under certain conditions) one to gain code execution (and elevation of privileges to the level of privilege held by the vulnerable…

  • CVE-2020-5992HigNov 11, 2020
    risk 0.51cvss 7.8epss 0.00

    NVIDIA GeForce NOW application software on Windows, all versions prior to 2.0.25.119, contains a vulnerability in its open-source software dependency in which the OpenSSL library is vulnerable to binary planting attacks by a local user, which may lead to code execution or…

  • CVE-2020-25174HigNov 6, 2020
    risk 0.51cvss 7.8epss 0.00

    A DLL hijacking vulnerability in the B. Braun OnlineSuite Version AP 3.0 and earlier allows local attackers to execute code on the system as a high privileged user.

  • CVE-2020-27708HigNov 2, 2020
    risk 0.51cvss 7.8epss 0.01

    A vulnerability exists in the Origin Client that could allow a non-Administrative user to elevate their access to either Administrator or System. Once the user has obtained elevated access, they may be able to take control of the system and perform actions otherwise reserved for…

  • CVE-2019-19115HigOct 8, 2020
    risk 0.51cvss 7.8epss 0.01

    An escalation of privilege vulnerability in Nahimic APO Software Component Driver 1.4.2, 1.5.0, 1.5.1, 1.6.1 and 1.6.2 allows an attacker to execute code with SYSTEM privileges.