VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,213)

page 33 of 61
  • CVE-2024-13946MedMay 22, 2025
    risk 0.47cvss 6.8epss 0.01

    DLL's are not digitally signed when loaded in ASPECT's configuration toolset exposing the application to binary planting during device commissioning.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

  • CVE-2023-31358HigMay 13, 2025
    risk 0.47cvss 7.3epss 0.00

    A DLL hijacking vulnerability in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2025-29803HigApr 12, 2025
    risk 0.47cvss 7.3epss 0.01

    Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally.

  • CVE-2025-2630HigApr 9, 2025
    risk 0.47cvss 7.3epss 0.00

    There is a DLL hijacking vulnerability due to an uncontrolled search path that exists in NI LabVIEW. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to insert a malicious DLL into the uncontrolled search path. This…

  • CVE-2025-2629HigApr 9, 2025
    risk 0.47cvss 7.3epss 0.00

    There is a DLL hijacking vulnerability due to an uncontrolled search path that exists in NI LabVIEW when loading NI Error Reporting. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to insert a malicious DLL into the…

  • CVE-2025-26631HigMar 11, 2025
    risk 0.47cvss 7.3epss 0.01

    Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally.

  • CVE-2025-25003HigMar 11, 2025
    risk 0.47cvss 7.3epss 0.00

    Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24998HigMar 11, 2025
    risk 0.47cvss 7.3epss 0.00

    Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.

  • CVE-2022-28339HigFeb 22, 2025
    risk 0.47cvss 7.3epss 0.00

    Trend Micro HouseCall for Home Networks version 5.3.1302 and below contains an uncontrolled search patch element vulnerability that could allow an attacker with low user privileges to create a malicious DLL that could lead to escalated privileges.

  • CVE-2024-57964HigFeb 18, 2025
    risk 0.47cvss 7.3epss 0.00

    Insecure Loading of Dynamic Link Libraries have been discovered in HVAC Energy Saving Program, which could allow local attackers to potentially disclose information or execute arbitray code on affected systems. This issue affects HVAC Energy Saving Program:.

  • CVE-2024-57963HigFeb 18, 2025
    risk 0.47cvss 7.3epss 0.00

    Insecure Loading of Dynamic Link Libraries have been discovered in USB-CONVERTERCABLE DRIVER, which could allow local attackers to potentially disclose information or execute arbitray code on affected systems. This issue affects USB-CONVERTERCABLE DRIVER:.

  • CVE-2023-31361HigFeb 11, 2025
    risk 0.47cvss 7.3epss 0.00

    A DLL hijacking vulnerability in AMD Integrated Management Technology (AIM-T) Manageability Service could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

  • CVE-2024-57426HigFeb 6, 2025
    risk 0.47cvss 7.3epss 0.00

    NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a malicious DLL in a directory where the application loads dependencies. This vulnerability arises due to the improper validation of dynamically loaded libraries.

  • CVE-2024-30376HigNov 22, 2024
    risk 0.47cvss 7.3epss 0.00

    Famatech Advanced IP Scanner Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Famatech Advanced IP Scanner. An attacker must first obtain the ability to…

  • CVE-2024-47942HigNov 12, 2024
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 9). The affected applications suffer from a DLL hijacking vulnerability. This could allow an attacker to execute arbitrary code via placing a crafted DLL file on the system.

  • CVE-2024-49391HigOct 17, 2024
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.

  • CVE-2024-49390HigOct 17, 2024
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.

  • CVE-2024-45246HigOct 6, 2024
    risk 0.47cvss 7.3epss 0.00

    Diebold Nixdorf – CWE-427: Uncontrolled Search Path Element

  • CVE-2024-20430HigSep 12, 2024
    risk 0.47cvss 7.3epss 0.00

    A vulnerability in Cisco Meraki Systems Manager (SM) Agent for Windows could allow an authenticated, local attacker to execute arbitrary code with elevated privileges. This vulnerability is due to incorrect handling of directory search paths at runtime. A low-privileged…

  • CVE-2024-34019HigAug 29, 2024
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 4569.