VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,233)

page 34 of 62
  • CVE-2025-2629HigApr 9, 2025
    risk 0.47cvss 7.3epss 0.00

    There is a DLL hijacking vulnerability due to an uncontrolled search path that exists in NI LabVIEW when loading NI Error Reporting. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to insert a malicious DLL into the…

  • CVE-2025-26631HigMar 11, 2025
    risk 0.47cvss 7.3epss 0.01

    Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally.

  • CVE-2025-25003HigMar 11, 2025
    risk 0.47cvss 7.3epss 0.00

    Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24998HigMar 11, 2025
    risk 0.47cvss 7.3epss 0.00

    Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.

  • CVE-2022-28339HigFeb 22, 2025
    risk 0.47cvss 7.3epss 0.00

    Trend Micro HouseCall for Home Networks version 5.3.1302 and below contains an uncontrolled search patch element vulnerability that could allow an attacker with low user privileges to create a malicious DLL that could lead to escalated privileges.

  • CVE-2024-57964HigFeb 18, 2025
    risk 0.47cvss 7.3epss 0.00

    Insecure Loading of Dynamic Link Libraries have been discovered in HVAC Energy Saving Program, which could allow local attackers to potentially disclose information or execute arbitray code on affected systems. This issue affects HVAC Energy Saving Program:.

  • CVE-2024-57963HigFeb 18, 2025
    risk 0.47cvss 7.3epss 0.00

    Insecure Loading of Dynamic Link Libraries have been discovered in USB-CONVERTERCABLE DRIVER, which could allow local attackers to potentially disclose information or execute arbitray code on affected systems. This issue affects USB-CONVERTERCABLE DRIVER:.

  • CVE-2023-31361HigFeb 11, 2025
    risk 0.47cvss 7.3epss 0.00

    A DLL hijacking vulnerability in AMD Integrated Management Technology (AIM-T) Manageability Service could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

  • CVE-2024-57426HigFeb 6, 2025
    risk 0.47cvss 7.3epss 0.00

    NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a malicious DLL in a directory where the application loads dependencies. This vulnerability arises due to the improper validation of dynamically loaded libraries.

  • CVE-2024-30376HigNov 22, 2024
    risk 0.47cvss 7.3epss 0.00

    Famatech Advanced IP Scanner Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Famatech Advanced IP Scanner. An attacker must first obtain the ability to…

  • CVE-2024-47942HigNov 12, 2024
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 9). The affected applications suffer from a DLL hijacking vulnerability. This could allow an attacker to execute arbitrary code via placing a crafted DLL file on the system.

  • CVE-2024-49391HigOct 17, 2024
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.

  • CVE-2024-49390HigOct 17, 2024
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.

  • CVE-2024-45246HigOct 6, 2024
    risk 0.47cvss 7.3epss 0.00

    Diebold Nixdorf – CWE-427: Uncontrolled Search Path Element

  • CVE-2024-20430HigSep 12, 2024
    risk 0.47cvss 7.3epss 0.00

    A vulnerability in Cisco Meraki Systems Manager (SM) Agent for Windows could allow an authenticated, local attacker to execute arbitrary code with elevated privileges. This vulnerability is due to incorrect handling of directory search paths at runtime. A low-privileged…

  • CVE-2024-34019HigAug 29, 2024
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 4569.

  • CVE-2024-34017HigAug 29, 2024
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 4569.

  • CVE-2023-31348HigAug 13, 2024
    risk 0.47cvss 7.3epss 0.00

    A DLL hijacking vulnerability in AMD μProf could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2024-37142HigJul 31, 2024
    risk 0.47cvss 7.3epss 0.00

    Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL or symbolic link exploitation, leading to arbitrary code execution and…

  • CVE-2024-32857HigJul 31, 2024
    risk 0.47cvss 7.3epss 0.00

    Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL or symbolic link exploitation, leading to arbitrary code execution and…