VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,213)

page 46 of 61
  • CVE-2024-6769MedSep 26, 2024
    risk 0.44cvss 6.7epss 0.01

    A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious authenticated attacker to elevate from a medium integrity process…

  • CVE-2024-8766MedSep 16, 2024
    risk 0.44cvss 6.7epss 0.00

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 38235, Acronis Cyber Protect 16 (Windows) before build 39169.

  • CVE-2024-34153MedSep 16, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-8441MedSep 10, 2024
    risk 0.44cvss 6.7epss 0.00

    An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin privileges to escalate their privileges to SYSTEM.

  • CVE-2024-29015MedAug 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) VTune(TM) Profiler software before versions 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-28953MedAug 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some EMON software before version 11.44 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-28887MedAug 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) IPP software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-28876MedAug 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for some Intel(R) MPI Library software before version 2021.12 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-28172MedAug 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for some Intel(R) Trace Analyzer and Collector software before version 2022.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-28046MedAug 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) GPA software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-26027MedAug 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for some Intel(R) Simics Package Manager software before version 1.8.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-24977MedAug 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for some Intel(R) License Manager for FLEXlm product software before version 11.19.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-23909MedAug 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) FPGA SDK for OpenCL(TM) software technology may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-23907MedAug 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) High Level Synthesis Compiler software before version 23.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-23491MedAug 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-23489MedAug 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for some Intel(R) VROC software before version 8.6.0.1191 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-22376MedAug 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in some installation software for Intel(R) Ethernet Adapter Driver Pack before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-22184MedAug 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for some Intel(R) Quartus(R) Prime Pro Edition Design Software before version 24.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-21857MedAug 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for some Intel(R) oneAPI Compiler software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-21784MedAug 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for some Intel(R) IPP Cryptography software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access.