VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,213)

page 25 of 61
  • CVE-2020-8146HigApr 1, 2020
    risk 0.51cvss 7.8epss 0.01

    In UniFi Video v3.10.1 (for Windows 7/8/10 x64) there is a Local Privileges Escalation to SYSTEM from arbitrary file deletion and DLL hijack vulnerabilities. The issue was fixed by adjusting the .tsExport folder when the controller is running on Windows and adjusting the…

  • CVE-2020-3803HigMar 25, 2020
    risk 0.51cvss 7.8epss 0.01

    Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and 2015.006.30510 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to…

  • CVE-2020-10649HigMar 25, 2020
    risk 0.51cvss 7.8epss 0.01

    DevActSvc.exe in ASUS Device Activation before 1.0.7.0 for Windows 10 notebooks and PCs could lead to unsigned code execution with no additional restrictions when a user puts an application at a particular path with a particular file name.

  • CVE-2020-7474HigMar 23, 2020
    risk 0.51cvss 7.8epss 0.00

    A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProSoft Configurator (v1.002 and prior), for the PMEPXM0100 (H) module, which could cause the execution of untrusted code when using double click to open a project file which may trigger execution of a malicious…

  • CVE-2020-9290HigMar 15, 2020
    risk 0.51cvss 7.8epss 0.01

    An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may allow a local attacker with control over the directory in which FortiClientOnlineInstaller.exe and FortiClientVPNOnlineInstaller.exe resides to execute arbitrary code on the…

  • CVE-2020-9287HigMar 15, 2020
    risk 0.51cvss 7.8epss 0.01

    An Unsafe Search Path vulnerability in FortiClient EMS online installer 6.2.1 and below may allow a local attacker with control over the directory in which FortiClientEMSOnlineInstaller.exe resides to execute arbitrary code on the system via uploading malicious Filter Library…

  • CVE-2020-8469HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Password Manager for Windows version 5.0 is affected by a DLL hijacking vulnerability would could potentially allow an attacker privleged escalation.

  • CVE-2020-0565HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path in Intel(R) Graphics Drivers before version 26.20.100.7158 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-0515HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path element in the installer for Intel(R) Graphics Drivers before versions 26.20.100.7584, 15.45.30.5103, 15.40.44.5107, 15.36.38.5117, and 15.33.49.5100 may allow an authenticated user to potentially enable escalation of privilege via local access

  • CVE-2020-8601HigFeb 20, 2020
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Vulnerability Protection 2.0 is affected by a vulnerability that could allow an attack to use the product installer to load other DLL files located in the same directory.

  • CVE-2020-8959HigFeb 19, 2020
    risk 0.51cvss 7.8epss 0.00

    Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking.

  • CVE-2020-5821HigFeb 11, 2020
    risk 0.51cvss 7.8epss 0.00

    Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a DLL injection vulnerability, which is a type of issue whereby an individual attempts to…

  • CVE-2019-20406HigFeb 6, 2020
    risk 0.51cvss 7.8epss 0.00

    The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a directory in the global path environmental variable variable…

  • CVE-2019-20400HigFeb 6, 2020
    risk 0.51cvss 7.8epss 0.00

    The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directory in the global path environmental variable can inject code into via a DLL hijacking vulnerability.

  • CVE-2019-20358HigJan 30, 2020
    risk 0.51cvss 7.8epss 0.05

    Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed. Another attack vector similar to…

  • CVE-2013-0725HigJan 30, 2020
    risk 0.51cvss 7.8epss 0.00

    ERDAS ER Viewer 13.0 has dwmapi.dll and irml.dll libraries arbitrary code execution vulnerabilities

  • CVE-2019-6858HigJan 22, 2020
    risk 0.51cvss 7.8epss 0.00

    A CWE-427:Uncontrolled Search Path Element vulnerability exists in MSX Configurator (Software Version prior to V1.0.8.1), which could cause privilege escalation when injecting a malicious DLL.

  • CVE-2016-6592HigJan 14, 2020
    risk 0.51cvss 7.8epss 0.01

    A vulnerability was found in Symantec Norton Download Manager versions prior to 5.6. A remote user can create a specially crafted DLL file that, when placed on the target user's system, will cause the Norton Download Manager component to load the remote user's DLL instead of the…

  • CVE-2016-5311HigJan 9, 2020
    risk 0.51cvss 7.8epss 0.01

    A Privilege Escalation vulnerability exists in Symantec Norton Antivirus, Norton AntiVirus with Backup, Norton Security, Norton Security with Backup, Norton Internet Security, Norton 360, Endpoint Protection Small Business Edition Cloud, and Endpoint Protection Cloud Client due…

  • CVE-2019-5539HigDec 23, 2019
    risk 0.51cvss 7.8epss 0.00

    VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL hijacking vulnerability due to insecure loading of a DLL by Cortado Thinprint. Successful exploitation of this issue may allow attackers with normal…