VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,213)

page 31 of 61
  • CVE-2016-4526HigSep 19, 2016
    risk 0.49cvss 7.5epss 0.00

    ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in the package directory.

  • CVE-2026-47937HigJun 9, 2026
    risk 0.48cvss 7.4epss 0.00

    Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…

  • CVE-2026-2713HigMar 10, 2026
    risk 0.48cvss 7.4epss 0.00

    IBM Trusteer Rapport installer 3.5.2309.290 IBM Trusteer Rapport could allow a local attacker to execute arbitrary code on the system, caused by DLL uncontrolled search path element vulnerability. By placing a specially crafted file in a compromised folder, an attacker could…

  • CVE-2025-29802HigApr 8, 2025
    risk 0.48cvss 7.3epss 0.01

    Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24039HigFeb 11, 2025
    risk 0.48cvss 7.3epss 0.01

    Visual Studio Code Elevation of Privilege Vulnerability

  • CVE-2025-21206HigFeb 11, 2025
    risk 0.48cvss 7.3epss 0.01

    Visual Studio Installer Elevation of Privilege Vulnerability

  • CVE-2024-22450HigApr 10, 2024
    risk 0.48cvss 7.4epss 0.00

    Dell Alienware Command Center, versions prior to 6.2.7.0, contain an uncontrolled search path element vulnerability. A local malicious user could potentially inject malicious files in the file search path, leading to system compromise.

  • CVE-2024-20338HigMar 6, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability in the ISE Posture (System Scan) module of Cisco Secure Client for Linux could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to the use of an uncontrolled search path element. An attacker could…

  • CVE-2022-32223HigJul 14, 2022
    risk 0.48cvss 7.3epss 0.02

    Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnerability can be exploited if the victim has the following dependencies on a Windows machine:* OpenSSL has been installed and “C:\Program Files\Common…

  • CVE-2021-44226HigMar 23, 2022
    risk 0.48cvss 7.3epss 0.01

    Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user before Synapse is installed. The unprivileged user may have placed Trojan horse…

  • CVE-2022-0129HigJan 11, 2022
    risk 0.48cvss 7.4epss 0.00

    Uncontrolled search path element vulnerability in McAfee TechCheck prior to 4.0.0.2 allows a local administrator to load their own Dynamic Link Library (DLL) gaining elevation of privileges to system user. This was achieved through placing the malicious DLL in the same directory…

  • CVE-2021-35982HigSep 29, 2021
    risk 0.48cvss 7.3epss 0.02

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Uncontrolled Search Path Element vulnerability. A local attacker with non-administrative privileges can plant a malicious DLL to achieve…

  • CVE-2021-28581HigSep 8, 2021
    risk 0.48cvss 7.3epss 0.01

    Adobe Creative Cloud Desktop 3.5 (and earlier) is affected by an uncontrolled search path vulnerability that could result in elevation of privileges. Exploitation of this issue requires user interaction in that a victim must log on to the attacker's local machine.

  • CVE-2021-28636HigAug 20, 2021
    risk 0.48cvss 7.3epss 0.02

    Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Uncontrolled Search Path Element vulnerability. An attacker with access to the victim's C:/ folder could leverage this vulnerability to…

  • CVE-2020-7360HigAug 13, 2020
    risk 0.48cvss 7.4epss 0.00

    An Uncontrolled Search Path Element (CWE-427) vulnerability in SmartControl version 4.3.15 and versions released before April 15, 2020 may allow an authenticated user to escalate privileges by placing a specially crafted DLL file in the search path. This issue was fixed in…

  • CVE-2019-1855HigJul 4, 2019
    risk 0.48cvss 7.3epss 0.02

    A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Jabber for Windows could allow an authenticated, local attacker to perform a DLL preloading attack. To exploit this vulnerability, the attacker would need to have valid credentials on the…

  • CVE-2026-6645HigJun 22, 2026
    risk 0.47cvss epss 0.00

    An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The application, which typically operates with high-level system privileges, attempts to perform an internal validation check by invoking a…

  • CVE-2026-11958HigJun 18, 2026
    risk 0.47cvss epss 0.00

    Local privilege escalation by loading DLLs from a shared temporary directory in ANSSI’s DFIR-ORC, versions 10.2.7 and prior. An attacker with prior access to the system, can place a malicious DLL in C:\Windows\Temp and wait for the application to be executed. Because DFIR-ORC…

  • CVE-2026-41567HigJun 5, 2026
    risk 0.47cvss 7.2epss 0.00

    Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries…

  • CVE-2026-50033HigJun 3, 2026
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.