VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,213)

page 42 of 61
  • CVE-2025-13665MedDec 12, 2025
    risk 0.44cvss 6.7epss 0.00

    The System Console Utility for Windows is vulnerable to a DLL planting vulnerability

  • CVE-2025-13668MedDec 11, 2025
    risk 0.44cvss 6.7epss 0.00

    A potential security vulnerability in Quartus® Prime Pro Edition Design Software may allow escalation of privilege.

  • CVE-2025-13664MedDec 11, 2025
    risk 0.44cvss 6.7epss 0.00

    A potential security vulnerability in Quartus® Prime Standard Edition Design Software may allow escalation of privilege.

  • CVE-2025-35972MedNov 11, 2025
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for the Intel MPI Library before version 2021.16 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege.…

  • CVE-2025-32038MedNov 11, 2025
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for some FPGA Support Package for the Intel oneAPI DPC++C++ Compiler software before version 2025.0.1 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high…

  • CVE-2025-32001MedNov 11, 2025
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for the Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable…

  • CVE-2025-31931MedNov 11, 2025
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for the Instrumentation and Tracing Technology API (ITT API) software before version 3.25.4 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity…

  • CVE-2025-31647MedNov 11, 2025
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for some Intel(R) Graphics Software before version 25.22.1502.2 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation…

  • CVE-2025-31645MedNov 11, 2025
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for some System Event Log Viewer Utility software for all versions within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable…

  • CVE-2025-30506MedNov 11, 2025
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for some Intel Driver and Support Assistant before version 25.2 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable local code…

  • CVE-2025-30182MedNov 11, 2025
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for some Intel(R) Distribution for Python software installers before version 2025.2.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack…

  • CVE-2025-25059MedNov 11, 2025
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity…

  • CVE-2025-24842MedNov 11, 2025
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for the Intel(R) System Support Utility before version 4.1.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a high complexity attack may enable local code…

  • CVE-2025-24491MedNov 11, 2025
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for some Intel(R) Killer(TM) Performance Suite software before version killer 4.0 40.25.509.1465 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high…

  • CVE-2025-20065MedNov 11, 2025
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for some Display Virtualization for Windows OS software before version 1797 within Ring 2: Device Drivers may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable…

  • CVE-2025-20050MedNov 11, 2025
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable local…

  • CVE-2025-57716MedOct 14, 2025
    risk 0.44cvss 6.7epss 0.00

    An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local low privileged user to perform a DLL hijacking attack via placing a malicious DLL to the FortiClient Online Installer…

  • CVE-2025-32919HigOct 9, 2025
    risk 0.44cvss 7.8epss 0.00

    Use of an insecure temporary directory in the Windows License plugin for the Checkmk Windows Agent allows Privilege Escalation. This issue affects Checkmk: from 2.4.0 before 2.4.0p13, from 2.3.0 before 2.3.0p38, from 2.2.0 before 2.2.0p46, and all versions of 2.1.0 (EOL).

  • CVE-2025-23355MedOct 1, 2025
    risk 0.44cvss 6.7epss 0.00

    NVIDIA Nsight Graphics for Windows contains a vulnerability in an ngfx component, where an attacker could cause a DLL highjacking attack. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, data tampering, and denial of service.

  • CVE-2025-55671HigSep 5, 2025
    risk 0.44cvss 7.8epss 0.00

    Uncontrolled search path element issue exists in TkEasyGUI versions prior to v1.0.22. If this vulnerability is exploited, arbitrary code may be executed with the privilege of running the program.