VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,213)

page 26 of 61
  • CVE-2019-19689HigDec 18, 2019
    risk 0.51cvss 7.8epss 0.01

    Trend Micro HouseCall for Home Networks (versions below 5.3.0.1063) could be exploited via a DLL Hijack related to a vulnerability on the packer that the program uses.

  • CVE-2019-18670HigDec 17, 2019
    risk 0.51cvss 7.8epss 0.01

    In the Quick Access Service (QAAdminAgent.exe) in Acer Quick Access V2.01.3000 through 2.01.3027 and V3.00.3000 through V3.00.3008, a REGULAR user can load an arbitrary unsigned DLL into the signed service's process, which is running as NT AUTHORITY\SYSTEM. This is a DLL…

  • CVE-2019-19364HigDec 4, 2019
    risk 0.51cvss 7.8epss 0.00

    A weak malicious user can escalate its privilege whenever CatalystProductionSuite.2019.1.exe (version 1.1.0.21) and CatalystBrowseSuite.2019.1.exe (version 1.1.0.21) installers run. The vulnerability is in the form of DLL Hijacking. The installers try to load DLLs that don’t…

  • CVE-2019-15638HigDec 4, 2019
    risk 0.51cvss 7.8epss 0.00

    COPA-DATA zenone32 zenon Editor through 8.10 has an Uncontrolled Search Path Element.

  • CVE-2019-7365HigDec 3, 2019
    risk 0.51cvss 7.8epss 0.00

    DLL preloading vulnerability in Autodesk Desktop Application versions 7.0.16.29 and earlier. An attacker may trick a user into downloading a malicious DLL file into the working directory, which may then leverage a DLL preloading vulnerability and execute code on the system.

  • CVE-2019-18215HigNov 18, 2019
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in signmgr.dll 6.5.0.819 in Comodo Internet Security through 12.0. A DLL Preloading vulnerability allows an attacker to implant an unsigned DLL named iLog.dll in a partially unprotected product directory. This DLL is then loaded into a high-privileged…

  • CVE-2019-7962HigNov 14, 2019
    risk 0.51cvss 7.8epss 0.01

    Adobe Illustrator CC versions 23.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.

  • CVE-2019-7960HigNov 14, 2019
    risk 0.51cvss 7.8epss 0.01

    Adobe Animate CC versions 19.2.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.

  • CVE-2019-5701HigNov 9, 2019
    risk 0.51cvss 7.8epss 0.01

    NVIDIA GeForce Experience, all versions prior to 3.20.0.118, contains a vulnerability when GameStream is enabled in which an attacker with local system access can load the Intel graphics driver DLLs without validating the path or signature (also known as a binary planting or DLL…

  • CVE-2019-6692HigOct 24, 2019
    risk 0.51cvss 7.8epss 0.01

    A malicious DLL preload vulnerability in Fortinet FortiClient for Windows 6.2.0 and below allows a privileged attacker to perform arbitrary code execution via forging that DLL.

  • CVE-2019-17093HigOct 23, 2019
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Avast antivirus before 19.8 and AVG antivirus before 19.8. A DLL Preloading vulnerability allows an attacker to implant %WINDIR%\system32\wbemcomn.dll, which is loaded into a protected-light process (PPL) and might bypass some of the self-defense…

  • CVE-2019-17665HigOct 16, 2019
    risk 0.51cvss 7.8epss 0.00

    NSA Ghidra before 9.0.2 is vulnerable to DLL hijacking because it loads jansi.dll from the current working directory.

  • CVE-2019-8076HigSep 12, 2019
    risk 0.51cvss 7.8epss 0.04

    Adobe application manager installer version 10.0 have an Insecure Library Loading (DLL hijacking) vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user.

  • CVE-2019-11773HigSep 12, 2019
    risk 0.51cvss 7.8epss 0.00

    Prior to 0.1, AIX builds of Eclipse OMR contain unused RPATHs which may facilitate code injection and privilege elevation by local users.

  • CVE-2019-4447HigAug 26, 2019
    risk 0.51cvss 7.8epss 0.00

    IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum_debug is a setuid root binary which trusts the PATH environment variable. A low privileged user can execute arbitrary commands as root by altering the PATH…

  • CVE-2019-7364HigAug 23, 2019
    risk 0.51cvss 7.8epss 0.02

    DLL preloading vulnerability in versions 2017, 2018, 2019, and 2020 of Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D and version 2017 of AutoCAD P&ID. An…

  • CVE-2019-7362HigAug 23, 2019
    risk 0.51cvss 7.8epss 0.01

    DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a DLL preloading vulnerability, which may result in code execution.

  • CVE-2019-14686HigAug 21, 2019
    risk 0.51cvss 7.8epss 0.01

    A DLL hijacking vulnerability exists in the Trend Micro Security's 2019 consumer family of products (v15) Folder Shield component and the standalone Trend Micro Ransom Buster (1.0) tool in which, if exploited, would allow an attacker to load a malicious DLL, leading to elevated…

  • CVE-2019-14687HigAug 20, 2019
    risk 0.51cvss 7.8epss 0.02

    A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14684.

  • CVE-2019-14684HigAug 20, 2019
    risk 0.51cvss 7.8epss 0.01

    A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14687.