VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,213)

page 4 of 61
  • CVE-2022-4313HigMar 15, 2023
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was reported where through modifying the scan variables, an authenticated user in Tenable products, that has Scan Policy Configuration roles, could manipulate audit policy variables to execute arbitrary commands on credentialed scan targets.

  • CVE-2023-23554HigMar 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Uncontrolled search path element vulnerability exists in pg_ivm versions prior to 1.5.1. When refreshing an IMMV, pg_ivm executes functions without specifying schema names. Under certain conditions, pg_ivm may be tricked to execute unexpected functions from other schemas with…

  • CVE-2022-43440HigFeb 9, 2023
    risk 0.57cvss 8.8epss 0.00

    Uncontrolled Search Path Element in Checkmk Agent in Tribe29 Checkmk before 2.1.0p1, before 2.0.0p25 and before 1.6.0p29 on a Checkmk server allows the site user to escalate privileges via a manipulated unixcat executable

  • CVE-2022-36930HigJan 9, 2023
    risk 0.57cvss 8.8epss 0.00

    Zoom Rooms for Windows installers before version 5.13.0 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability in an attack chain to escalate their privileges to the SYSTEM user.

  • CVE-2022-36924HigNov 17, 2022
    risk 0.57cvss 8.8epss 0.00

    The Zoom Rooms Installer for Windows prior to 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to the SYSTEM user.

  • CVE-2022-2333HigSep 16, 2022
    risk 0.57cvss 8.8epss 0.01

    If an attacker manages to trick a valid user into loading a malicious DLL, the attacker may be able to achieve code execution in Honeywell SoftMaster version 4.51 application’s context and permissions.

  • CVE-2017-20123HigJun 30, 2022
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Viscosity 1.6.7. It has been classified as critical. This affects an unknown part of the component DLL Handler. The manipulation leads to untrusted search path. It is possible to initiate the attack remotely. The exploit has been disclosed to the…

  • CVE-2021-42743HigMay 6, 2022
    risk 0.57cvss 8.8epss 0.00

    A misconfiguration in the node default path allows for local privilege escalation from a lower privileged user to the Splunk user in Splunk Enterprise versions before 8.1.1 on Windows.

  • CVE-2021-28822HigMar 23, 2021
    risk 0.57cvss 8.8epss 0.00

    The Enterprise Message Service Server (tibemsd), Enterprise Message Service Central Administration (tibemsca), Enterprise Message Service JSON configuration generator (tibemsconf2json), and Enterprise Message Service C API components of TIBCO Software Inc.'s TIBCO Enterprise…

  • CVE-2021-28820HigMar 23, 2021
    risk 0.57cvss 8.8epss 0.00

    The FTL Server (tibftlserver), FTL C API, FTL Golang API, FTL Java API, and FTL .Net API components of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contain a vulnerability that theoretically allows a low…

  • CVE-2020-15663HigOct 1, 2020
    risk 0.57cvss 8.8epss 0.03

    If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute updater.exe from the install location with system privileges. Although the Mozilla Maintenance Service does ensure that updater.exe is signed by Mozilla, the version could have…

  • CVE-2019-20856CriJun 19, 2020
    risk 0.57cvss 9.8epss 0.01

    An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection.

  • CVE-2020-10616HigMay 14, 2020
    risk 0.57cvss 8.8epss 0.02

    Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC does not specify the path of multiple imported .dll files. Therefore, an attacker can replace them and execute code whenever the service starts.

  • CVE-2017-7966HigJun 7, 2017
    risk 0.57cvss 8.8epss 0.02

    A DLL Hijacking vulnerability in the programming software in Schneider Electric's SoMachine HVAC v2.1.0 allows a remote attacker to execute arbitrary code on the targeted system. The vulnerability exists due to the improper loading of a DLL.

  • CVE-2026-48388HigJul 28, 2026
    risk 0.56cvss 8.6epss 0.00

    Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory…

  • CVE-2026-34632HigApr 15, 2026
    risk 0.56cvss 8.6epss 0.00

    Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory…

  • CVE-2025-59887HigDec 26, 2025
    risk 0.56cvss 8.6epss 0.00

    Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the software package. This security issue has been fixed in the latest version of EUC which is available on the Eaton…

  • CVE-2025-59889HigOct 14, 2025
    risk 0.56cvss 8.6epss 0.00

    Improper authentication of library files in the Eaton IPP software installer could lead to arbitrary code execution of an attacker with the access to the software package.  This security issue has been fixed in the latest version of IPP which is available on the Eaton download…

  • CVE-2024-9499HigJan 24, 2025
    risk 0.56cvss 8.6epss 0.00

    DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress Win 98SE Dev Kit installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.

  • CVE-2024-9498HigJan 24, 2025
    risk 0.56cvss 8.6epss 0.00

    DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress SDK installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.