VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,213)

page 48 of 61
  • CVE-2023-39929MedMay 16, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Libva software maintained by Intel(R) before version 2.20.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-35192MedMay 16, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-39254MedMar 1, 2024
    risk 0.44cvss 6.7epss 0.00

    Dell Update Package (DUP), Versions prior to 4.9.10 contain an Uncontrolled Search Path vulnerability. A malicious user with local access to the system could potentially exploit this vulnerability to run arbitrary code as admin.

  • CVE-2023-49114MedFeb 26, 2024
    risk 0.44cvss 6.7epss 0.00

    A DLL hijacking vulnerability was identified in the Qognify VMS Client Viewer version 7.1 or higher, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL, if some specific pre-conditions are met.

  • CVE-2023-41091MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for some Intel(R) MPI Library Software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-40156MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in some Intel(R) SSU software before version 3.0.0.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-39932MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow a privillaged user to potentially enable escalation of privilege via local access.

  • CVE-2023-38566MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) ISPC software before version 1.21.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-36493MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) SDK for OpenCL(TM) Applications software may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-35769MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) CIP software before version 2.4.10577 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-35060MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) Battery Life Diagnostic Tool software before version 2.3.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-32646MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-32618MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-28745MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in Intel(R) QSFP+ Configuration Utility software, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-28407MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) XTU software before version 7.12.0.29 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-25779MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-24591MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) Binary Configuration Tool software before version 3.4.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-34430MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel Battery Life Diagnostic Tool software before version 2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-34350MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in some Intel(R) XTU software before version 7.12.0.15 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-33874MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) NUC 12 Pro Kits & Mini PCs - NUC12WS Intel(R) HID Event Filter Driver installation software before version 2.2.2.1 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.