VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,233)

page 25 of 62
  • CVE-2020-15722HigJul 21, 2020
    risk 0.51cvss 7.8epss 0.00

    In version 12.1.0.1004 and below of 360 Total Security,when TPI calls the browser process, there exists a local privilege escalation vulnerability. An attacker who could exploit DLL hijacking could execute arbitrary code on the Local system.

  • CVE-2020-12423HigJul 9, 2020
    risk 0.51cvss 7.8epss 0.00

    When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in the user's %PATH%, Firefox may have loaded the DLL, leading to arbitrary code execution. *Note: This issue only affects the Windows operating system; other…

  • CVE-2020-9100HigJul 6, 2020
    risk 0.51cvss 7.8epss 0.00

    Earlier than HiSuite 10.1.0.500 have a DLL hijacking vulnerability. This vulnerability exists due to some DLL file is loaded by HiSuite improperly. And it allows an attacker to load this DLL file of the attacker's choosing.

  • CVE-2019-20419HigJul 3, 2020
    risk 0.51cvss 7.8epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to execute arbitrary code via a DLL hijacking vulnerability in Tomcat. The affected versions are before version 8.5.5, and from version 8.6.0 before 8.7.2.

  • CVE-2020-11613HigJun 11, 2020
    risk 0.51cvss 7.8epss 0.00

    Mids' Reborn Hero Designer 2.6.0.7 has an elevation of privilege vulnerability due to default and insecure permissions being set for the installation folder. By default, the Authenticated Users group has Modify permissions to the installation folder. Because of this, any user on…

  • CVE-2020-7585HigJun 10, 2020
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All versions < V9.2), SIMATIC STEP 7 V5.X (All versions < V5.6 SP2 HF3), SINAMICS STARTER (containing STEP 7 OEM version) (All…

  • CVE-2020-9858HigJun 9, 2020
    risk 0.51cvss 7.8epss 0.00

    A dynamic library loading issue was addressed with improved path searching. This issue is fixed in Windows Migration Assistant 2.2.0.0 (v. 1A11). Running the installer in an untrusted directory may result in arbitrary code execution.

  • CVE-2020-13110HigMay 16, 2020
    risk 0.51cvss 7.8epss 0.01

    The kerberos package before 1.0.0 for Node.js allows arbitrary code execution and privilege escalation via injection of malicious DLLs through use of the kerberos_sspi LoadLibrary() method, because of a DLL path search.

  • CVE-2020-10626HigMay 14, 2020
    risk 0.51cvss 7.8epss 0.01

    In Fazecast jSerialComm, Version 2.2.2 and prior, an uncontrolled search path element vulnerability could allow a malicious DLL file with the same name of any resident DLLs inside the software installation to execute arbitrary code.

  • CVE-2020-6244HigMay 12, 2020
    risk 0.51cvss 7.8epss 0.00

    SAP Business Client, version 7.0, allows an attacker after a successful social engineering attack to inject malicious code as a DLL file in untrusted directories that can be executed by the application, due to uncontrolled search path element. An attacker could thereby control…

  • CVE-2019-20781HigApr 29, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in LG Bridge before April 2019 on Windows. DLL Hijacking can occur.

  • CVE-2020-5740HigApr 22, 2020
    risk 0.51cvss 7.8epss 0.01

    Improper Input Validation in Plex Media Server on Windows allows a local, unauthenticated attacker to execute arbitrary Python code with SYSTEM privileges.

  • CVE-2020-8895HigApr 21, 2020
    risk 0.51cvss 7.8epss 0.00

    Untrusted Search Path vulnerability in the windows installer of Google Earth Pro versions prior to 7.3.3 allows an attacker to insert malicious local files to execute unauthenticated remote code on the targeted system.

  • CVE-2019-20769HigApr 17, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in LG PC Suite for LG G3 and earlier (aka LG PC Suite v5.3.27 and earlier). DLL Hijacking can occur via a Trojan horse DLL in the current working directory. The LG ID is LVE-MOT-190001 (November 2019).

  • CVE-2020-8146HigApr 1, 2020
    risk 0.51cvss 7.8epss 0.01

    In UniFi Video v3.10.1 (for Windows 7/8/10 x64) there is a Local Privileges Escalation to SYSTEM from arbitrary file deletion and DLL hijack vulnerabilities. The issue was fixed by adjusting the .tsExport folder when the controller is running on Windows and adjusting the…

  • CVE-2020-3803HigMar 25, 2020
    risk 0.51cvss 7.8epss 0.01

    Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and 2015.006.30510 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to…

  • CVE-2020-10649HigMar 25, 2020
    risk 0.51cvss 7.8epss 0.01

    DevActSvc.exe in ASUS Device Activation before 1.0.7.0 for Windows 10 notebooks and PCs could lead to unsigned code execution with no additional restrictions when a user puts an application at a particular path with a particular file name.

  • CVE-2020-7474HigMar 23, 2020
    risk 0.51cvss 7.8epss 0.00

    A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProSoft Configurator (v1.002 and prior), for the PMEPXM0100 (H) module, which could cause the execution of untrusted code when using double click to open a project file which may trigger execution of a malicious…

  • CVE-2020-9290HigMar 15, 2020
    risk 0.51cvss 7.8epss 0.01

    An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may allow a local attacker with control over the directory in which FortiClientOnlineInstaller.exe and FortiClientVPNOnlineInstaller.exe resides to execute arbitrary code on the…

  • CVE-2020-9287HigMar 15, 2020
    risk 0.51cvss 7.8epss 0.01

    An Unsafe Search Path vulnerability in FortiClient EMS online installer 6.2.1 and below may allow a local attacker with control over the directory in which FortiClientEMSOnlineInstaller.exe resides to execute arbitrary code on the system via uploading malicious Filter Library…