VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,233)

page 28 of 62
  • CVE-2019-1010100HigJul 19, 2019
    risk 0.51cvss 7.8epss 0.02

    Akeo Consulting Rufus 3.0 and earlier is affected by: DLL search order hijacking. The impact is: Arbitrary code execution WITH escalation of privilege. The component is: Executable installers, portable executables (ALL executables on the web site). The attack vector is:…

  • CVE-2019-7956HigJul 18, 2019
    risk 0.51cvss 7.8epss 0.03

    Adobe Dreamweaver direct download installer versions 19.0 and below, 18.0 and below have an Insecure Library Loading (DLL hijacking) vulnerability. Successful exploitation could lead to Privilege Escalation in the context of the current user.

  • CVE-2019-6825HigJul 15, 2019
    risk 0.51cvss 7.8epss 0.01

    A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow a malicious DLL file, with the same name of any resident DLLs inside the software installation, to execute arbitrary code in all versions of…

  • CVE-2019-5629HigJul 13, 2019
    risk 0.51cvss 7.8epss 0.01

    Rapid7 Insight Agent, version 2.6.3 and prior, suffers from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when Insight Agent 2.6.3 and prior starts, the Python interpreter attempts to load python3.dll at "C:\DLLs\python3.dll," which normally…

  • CVE-2019-12575HigJul 11, 2019
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The root_runner.64 binary is setuid root. This binary executes /opt/pia/ruby/64/ruby,…

  • CVE-2019-5443HigJul 2, 2019
    risk 0.51cvss 7.8epss 0.01

    A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything…

  • CVE-2019-12280HigJun 25, 2019
    risk 0.51cvss 7.8epss 0.03

    PC-Doctor Toolbox before 7.3 has an Uncontrolled Search Path Element.

  • CVE-2019-12572HigJun 21, 2019
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client 1.0.2 (build 02363) for Windows could allow an authenticated, local attacker to run arbitrary code with elevated privileges. On startup, the PIA Windows service (pia-service.exe) loads the OpenSSL…

  • CVE-2019-12133HigJun 18, 2019
    risk 0.51cvss 7.8epss 0.02

    Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said products try to execute binaries such as sc.exe from the current…

  • CVE-2019-12177HigJun 3, 2019
    risk 0.51cvss 7.8epss 0.02

    Privilege escalation due to insecure directory permissions affecting ViveportDesktopService in HTC VIVEPORT before 1.0.0.36 allows local attackers to escalate privileges via DLL hijacking.

  • CVE-2019-7093HigMay 24, 2019
    risk 0.51cvss 7.8epss 0.03

    Creative Cloud Desktop Application (installer) versions 4.7.0.400 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.

  • CVE-2018-7840HigMay 22, 2019
    risk 0.51cvss 7.8epss 0.01

    A Uncontrolled Search Path Element (CWE-427) vulnerability exists in VideoXpert OpsCenter versions prior to 3.1 which could allow an attacker to cause the system to call an incorrect DLL.

  • CVE-2019-11644HigMay 17, 2019
    risk 0.51cvss 7.8epss 0.02

    In the F-Secure installer in F-Secure SAFE for Windows before 17.6, F-Secure Internet Security before 17.6, F-Secure Anti-Virus before 17.6, F-Secure Client Security Standard and Premium before 14.10, F-Secure PSB Workstation Security before 12.01, and F-Secure Computer…

  • CVE-2019-6564HigMay 9, 2019
    risk 0.51cvss 7.8epss 0.00

    GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to place malicious files within the installer file directory, which may allow an attacker to gain administrative privileges on a system during installation or upgrade.

  • CVE-2019-6546HigMay 9, 2019
    risk 0.51cvss 7.8epss 0.01

    GE Communicator, all versions prior to 4.0.517, allows an attacker to place malicious files within the working directory of the program, which may allow an attacker to manipulate widgets and UI elements.

  • CVE-2019-6534HigApr 11, 2019
    risk 0.51cvss 7.8epss 0.02

    The uncontrolled search path element vulnerability in Gemalto Sentinel UltraPro Client Library ux32w.dll Versions 1.3.0, 1.3.1, and 1.3.2 enables an attacker to load and execute a malicious file.

  • CVE-2019-9896HigMar 21, 2019
    risk 0.51cvss 7.8epss 0.01

    In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same directory as the executable.

  • CVE-2019-4094HigMar 21, 2019
    risk 0.51cvss 7.8epss 0.00

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege user full access to root by loading a malicious shared library. IBM X-Force ID: 158014.

  • CVE-2019-9634HigMar 8, 2019
    risk 0.51cvss 7.8epss 0.03

    Go through 1.12 on Windows misuses certain LoadLibrary functionality, leading to DLL injection.

  • CVE-2019-9116HigFeb 25, 2019
    risk 0.51cvss 7.8epss 0.01

    DLL hijacking is possible in Sublime Text 3 version 3.1.1 build 3176 on 32-bit Windows platforms because a Trojan horse api-ms-win-core-fibers-l1-1-1.dll or api-ms-win-core-localization-l1-2-1.dll file may be loaded if a victim uses sublime_text.exe to open a .txt file within an…