CWE-427
Uncontrolled Search Path Element
Description
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-38 · CAPEC-471
CVEs mapped to this weakness (1,213)
page 42 of 61| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-13665 | Med | 0.44 | 6.7 | 0.00 | Dec 12, 2025 | The System Console Utility for Windows is vulnerable to a DLL planting vulnerability | ||
| CVE-2025-13668 | Med | 0.44 | 6.7 | 0.00 | Dec 11, 2025 | A potential security vulnerability in Quartus® Prime Pro Edition Design Software may allow escalation of privilege. | ||
| CVE-2025-13664 | Med | 0.44 | 6.7 | 0.00 | Dec 11, 2025 | A potential security vulnerability in Quartus® Prime Standard Edition Design Software may allow escalation of privilege. | ||
| CVE-2025-35972 | Med | 0.44 | 6.7 | 0.00 | Nov 11, 2025 | Uncontrolled search path for the Intel MPI Library before version 2021.16 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege.… | ||
| CVE-2025-32038 | Med | 0.44 | 6.7 | 0.00 | Nov 11, 2025 | Uncontrolled search path for some FPGA Support Package for the Intel oneAPI DPC++C++ Compiler software before version 2025.0.1 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high… | ||
| CVE-2025-32001 | Med | 0.44 | 6.7 | 0.00 | Nov 11, 2025 | Uncontrolled search path for the Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable… | ||
| CVE-2025-31931 | Med | 0.44 | 6.7 | 0.00 | Nov 11, 2025 | Uncontrolled search path for the Instrumentation and Tracing Technology API (ITT API) software before version 3.25.4 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity… | ||
| CVE-2025-31647 | Med | 0.44 | 6.7 | 0.00 | Nov 11, 2025 | Uncontrolled search path for some Intel(R) Graphics Software before version 25.22.1502.2 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation… | ||
| CVE-2025-31645 | Med | 0.44 | 6.7 | 0.00 | Nov 11, 2025 | Uncontrolled search path for some System Event Log Viewer Utility software for all versions within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable… | ||
| CVE-2025-30506 | Med | 0.44 | 6.7 | 0.00 | Nov 11, 2025 | Uncontrolled search path for some Intel Driver and Support Assistant before version 25.2 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable local code… | ||
| CVE-2025-30182 | Med | 0.44 | 6.7 | 0.00 | Nov 11, 2025 | Uncontrolled search path for some Intel(R) Distribution for Python software installers before version 2025.2.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack… | ||
| CVE-2025-25059 | Med | 0.44 | 6.7 | 0.00 | Nov 11, 2025 | Uncontrolled search path for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity… | ||
| CVE-2025-24842 | Med | 0.44 | 6.7 | 0.00 | Nov 11, 2025 | Uncontrolled search path for the Intel(R) System Support Utility before version 4.1.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a high complexity attack may enable local code… | ||
| CVE-2025-24491 | Med | 0.44 | 6.7 | 0.00 | Nov 11, 2025 | Uncontrolled search path for some Intel(R) Killer(TM) Performance Suite software before version killer 4.0 40.25.509.1465 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high… | ||
| CVE-2025-20065 | Med | 0.44 | 6.7 | 0.00 | Nov 11, 2025 | Uncontrolled search path for some Display Virtualization for Windows OS software before version 1797 within Ring 2: Device Drivers may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable… | ||
| CVE-2025-20050 | Med | 0.44 | 6.7 | 0.00 | Nov 11, 2025 | Uncontrolled search path for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable local… | ||
| CVE-2025-57716 | Med | 0.44 | 6.7 | 0.00 | Oct 14, 2025 | An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local low privileged user to perform a DLL hijacking attack via placing a malicious DLL to the FortiClient Online Installer… | ||
| CVE-2025-32919 | Hig | 0.44 | 7.8 | 0.00 | Oct 9, 2025 | Use of an insecure temporary directory in the Windows License plugin for the Checkmk Windows Agent allows Privilege Escalation. This issue affects Checkmk: from 2.4.0 before 2.4.0p13, from 2.3.0 before 2.3.0p38, from 2.2.0 before 2.2.0p46, and all versions of 2.1.0 (EOL). | ||
| CVE-2025-23355 | Med | 0.44 | 6.7 | 0.00 | Oct 1, 2025 | NVIDIA Nsight Graphics for Windows contains a vulnerability in an ngfx component, where an attacker could cause a DLL highjacking attack. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, data tampering, and denial of service. | ||
| CVE-2025-55671 | Hig | 0.44 | 7.8 | 0.00 | Sep 5, 2025 | Uncontrolled search path element issue exists in TkEasyGUI versions prior to v1.0.22. If this vulnerability is exploited, arbitrary code may be executed with the privilege of running the program. |
- risk 0.44cvss 6.7epss 0.00
The System Console Utility for Windows is vulnerable to a DLL planting vulnerability
- risk 0.44cvss 6.7epss 0.00
A potential security vulnerability in Quartus® Prime Pro Edition Design Software may allow escalation of privilege.
- risk 0.44cvss 6.7epss 0.00
A potential security vulnerability in Quartus® Prime Standard Edition Design Software may allow escalation of privilege.
- risk 0.44cvss 6.7epss 0.00
Uncontrolled search path for the Intel MPI Library before version 2021.16 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege.…
- risk 0.44cvss 6.7epss 0.00
Uncontrolled search path for some FPGA Support Package for the Intel oneAPI DPC++C++ Compiler software before version 2025.0.1 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high…
- risk 0.44cvss 6.7epss 0.00
Uncontrolled search path for the Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable…
- risk 0.44cvss 6.7epss 0.00
Uncontrolled search path for the Instrumentation and Tracing Technology API (ITT API) software before version 3.25.4 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity…
- risk 0.44cvss 6.7epss 0.00
Uncontrolled search path for some Intel(R) Graphics Software before version 25.22.1502.2 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation…
- risk 0.44cvss 6.7epss 0.00
Uncontrolled search path for some System Event Log Viewer Utility software for all versions within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable…
- risk 0.44cvss 6.7epss 0.00
Uncontrolled search path for some Intel Driver and Support Assistant before version 25.2 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable local code…
- risk 0.44cvss 6.7epss 0.00
Uncontrolled search path for some Intel(R) Distribution for Python software installers before version 2025.2.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack…
- risk 0.44cvss 6.7epss 0.00
Uncontrolled search path for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity…
- risk 0.44cvss 6.7epss 0.00
Uncontrolled search path for the Intel(R) System Support Utility before version 4.1.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a high complexity attack may enable local code…
- risk 0.44cvss 6.7epss 0.00
Uncontrolled search path for some Intel(R) Killer(TM) Performance Suite software before version killer 4.0 40.25.509.1465 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high…
- risk 0.44cvss 6.7epss 0.00
Uncontrolled search path for some Display Virtualization for Windows OS software before version 1797 within Ring 2: Device Drivers may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable…
- risk 0.44cvss 6.7epss 0.00
Uncontrolled search path for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable local…
- risk 0.44cvss 6.7epss 0.00
An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local low privileged user to perform a DLL hijacking attack via placing a malicious DLL to the FortiClient Online Installer…
- risk 0.44cvss 7.8epss 0.00
Use of an insecure temporary directory in the Windows License plugin for the Checkmk Windows Agent allows Privilege Escalation. This issue affects Checkmk: from 2.4.0 before 2.4.0p13, from 2.3.0 before 2.3.0p38, from 2.2.0 before 2.2.0p46, and all versions of 2.1.0 (EOL).
- risk 0.44cvss 6.7epss 0.00
NVIDIA Nsight Graphics for Windows contains a vulnerability in an ngfx component, where an attacker could cause a DLL highjacking attack. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, data tampering, and denial of service.
- risk 0.44cvss 7.8epss 0.00
Uncontrolled search path element issue exists in TkEasyGUI versions prior to v1.0.22. If this vulnerability is exploited, arbitrary code may be executed with the privilege of running the program.