CWE-427
Uncontrolled Search Path Element
Description
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-38 · CAPEC-471
CVEs mapped to this weakness (1,213)
page 33 of 61| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-13946 | Med | 0.47 | 6.8 | 0.01 | May 22, 2025 | DLL's are not digitally signed when loaded in ASPECT's configuration toolset exposing the application to binary planting during device commissioning.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*. | ||
| CVE-2023-31358 | Hig | 0.47 | 7.3 | 0.00 | May 13, 2025 | A DLL hijacking vulnerability in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. | ||
| CVE-2025-29803 | Hig | 0.47 | 7.3 | 0.01 | Apr 12, 2025 | Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-2630 | Hig | 0.47 | 7.3 | 0.00 | Apr 9, 2025 | There is a DLL hijacking vulnerability due to an uncontrolled search path that exists in NI LabVIEW. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to insert a malicious DLL into the uncontrolled search path. This… | ||
| CVE-2025-2629 | Hig | 0.47 | 7.3 | 0.00 | Apr 9, 2025 | There is a DLL hijacking vulnerability due to an uncontrolled search path that exists in NI LabVIEW when loading NI Error Reporting. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to insert a malicious DLL into the… | ||
| CVE-2025-26631 | Hig | 0.47 | 7.3 | 0.01 | Mar 11, 2025 | Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-25003 | Hig | 0.47 | 7.3 | 0.00 | Mar 11, 2025 | Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-24998 | Hig | 0.47 | 7.3 | 0.00 | Mar 11, 2025 | Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. | ||
| CVE-2022-28339 | Hig | 0.47 | 7.3 | 0.00 | Feb 22, 2025 | Trend Micro HouseCall for Home Networks version 5.3.1302 and below contains an uncontrolled search patch element vulnerability that could allow an attacker with low user privileges to create a malicious DLL that could lead to escalated privileges. | ||
| CVE-2024-57964 | Hig | 0.47 | 7.3 | 0.00 | Feb 18, 2025 | Insecure Loading of Dynamic Link Libraries have been discovered in HVAC Energy Saving Program, which could allow local attackers to potentially disclose information or execute arbitray code on affected systems. This issue affects HVAC Energy Saving Program:. | ||
| CVE-2024-57963 | Hig | 0.47 | 7.3 | 0.00 | Feb 18, 2025 | Insecure Loading of Dynamic Link Libraries have been discovered in USB-CONVERTERCABLE DRIVER, which could allow local attackers to potentially disclose information or execute arbitray code on affected systems. This issue affects USB-CONVERTERCABLE DRIVER:. | ||
| CVE-2023-31361 | Hig | 0.47 | 7.3 | 0.00 | Feb 11, 2025 | A DLL hijacking vulnerability in AMD Integrated Management Technology (AIM-T) Manageability Service could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | ||
| CVE-2024-57426 | Hig | 0.47 | 7.3 | 0.00 | Feb 6, 2025 | NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a malicious DLL in a directory where the application loads dependencies. This vulnerability arises due to the improper validation of dynamically loaded libraries. | ||
| CVE-2024-30376 | Hig | 0.47 | 7.3 | 0.00 | Nov 22, 2024 | Famatech Advanced IP Scanner Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Famatech Advanced IP Scanner. An attacker must first obtain the ability to… | ||
| CVE-2024-47942 | Hig | 0.47 | 7.3 | 0.00 | Nov 12, 2024 | A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 9). The affected applications suffer from a DLL hijacking vulnerability. This could allow an attacker to execute arbitrary code via placing a crafted DLL file on the system. | ||
| CVE-2024-49391 | Hig | 0.47 | 7.3 | 0.00 | Oct 17, 2024 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24. | ||
| CVE-2024-49390 | Hig | 0.47 | 7.3 | 0.00 | Oct 17, 2024 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24. | ||
| CVE-2024-45246 | Hig | 0.47 | 7.3 | 0.00 | Oct 6, 2024 | Diebold Nixdorf – CWE-427: Uncontrolled Search Path Element | ||
| CVE-2024-20430 | Hig | 0.47 | 7.3 | 0.00 | Sep 12, 2024 | A vulnerability in Cisco Meraki Systems Manager (SM) Agent for Windows could allow an authenticated, local attacker to execute arbitrary code with elevated privileges. This vulnerability is due to incorrect handling of directory search paths at runtime. A low-privileged… | ||
| CVE-2024-34019 | Hig | 0.47 | 7.3 | 0.00 | Aug 29, 2024 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 4569. |
- risk 0.47cvss 6.8epss 0.01
DLL's are not digitally signed when loaded in ASPECT's configuration toolset exposing the application to binary planting during device commissioning.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
- risk 0.47cvss 7.3epss 0.00
A DLL hijacking vulnerability in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
- risk 0.47cvss 7.3epss 0.01
Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally.
- risk 0.47cvss 7.3epss 0.00
There is a DLL hijacking vulnerability due to an uncontrolled search path that exists in NI LabVIEW. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to insert a malicious DLL into the uncontrolled search path. This…
- risk 0.47cvss 7.3epss 0.00
There is a DLL hijacking vulnerability due to an uncontrolled search path that exists in NI LabVIEW when loading NI Error Reporting. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to insert a malicious DLL into the…
- risk 0.47cvss 7.3epss 0.01
Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally.
- risk 0.47cvss 7.3epss 0.00
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
- risk 0.47cvss 7.3epss 0.00
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
- risk 0.47cvss 7.3epss 0.00
Trend Micro HouseCall for Home Networks version 5.3.1302 and below contains an uncontrolled search patch element vulnerability that could allow an attacker with low user privileges to create a malicious DLL that could lead to escalated privileges.
- risk 0.47cvss 7.3epss 0.00
Insecure Loading of Dynamic Link Libraries have been discovered in HVAC Energy Saving Program, which could allow local attackers to potentially disclose information or execute arbitray code on affected systems. This issue affects HVAC Energy Saving Program:.
- risk 0.47cvss 7.3epss 0.00
Insecure Loading of Dynamic Link Libraries have been discovered in USB-CONVERTERCABLE DRIVER, which could allow local attackers to potentially disclose information or execute arbitray code on affected systems. This issue affects USB-CONVERTERCABLE DRIVER:.
- risk 0.47cvss 7.3epss 0.00
A DLL hijacking vulnerability in AMD Integrated Management Technology (AIM-T) Manageability Service could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
- risk 0.47cvss 7.3epss 0.00
NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a malicious DLL in a directory where the application loads dependencies. This vulnerability arises due to the improper validation of dynamically loaded libraries.
- risk 0.47cvss 7.3epss 0.00
Famatech Advanced IP Scanner Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Famatech Advanced IP Scanner. An attacker must first obtain the ability to…
- risk 0.47cvss 7.3epss 0.00
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 9). The affected applications suffer from a DLL hijacking vulnerability. This could allow an attacker to execute arbitrary code via placing a crafted DLL file on the system.
- risk 0.47cvss 7.3epss 0.00
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.
- risk 0.47cvss 7.3epss 0.00
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.
- risk 0.47cvss 7.3epss 0.00
Diebold Nixdorf – CWE-427: Uncontrolled Search Path Element
- risk 0.47cvss 7.3epss 0.00
A vulnerability in Cisco Meraki Systems Manager (SM) Agent for Windows could allow an authenticated, local attacker to execute arbitrary code with elevated privileges. This vulnerability is due to incorrect handling of directory search paths at runtime. A low-privileged…
- risk 0.47cvss 7.3epss 0.00
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 4569.