VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,213)

page 49 of 61
  • CVE-2023-32660MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) NUC Kit NUC6i7KYK Thunderbolt(TM) 3 Firmware Update Tool installation software before version 46 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-29504MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in some Intel(R) RealSense(TM) Dynamic Calibration software before version 2.13.1.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-29161MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-28740MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-28388MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in some Intel(R) Chipset Device Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-27513MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in some Intel(R) Server Information Retrieval Utility software before version 16.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-3252MedAug 29, 2023
    risk 0.44cvss 6.8epss 0.01

    An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges could alter logging variables to overwrite arbitrary files on the remote host with log data, which could lead to a denial of service condition.

  • CVE-2023-34355MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element for some Intel(R) Server Board M10JNP2SB integrated BMC video drivers before version 3.0 for Microsoft Windows and before version 1.13.4 for linux may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-29151MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in some Intel(R) PSR SDK before version 1.0.0.20 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-28823MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-28405MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in the Intel(R) Distribution of OpenVINO(TM) Toolkit before version 2022.3.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-25944MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in some Intel(R) VCUST Tool software downloaded before February 3nd 2023 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-24016MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in some Intel(R) Quartus(R) Prime Pro and Standard edition software for linux may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-23577MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element for some ITE Tech consumer infrared drivers before version 5.5.2.1 for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-22841MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Unquoted search path in the software installer for the System Firmware Update Utility (SysFwUpdt) for some Intel(R) Server Boards and Intel(R) Server Systems Based on Intel(R) 621A Chipset before version 16.0.7 may allow an authenticated user to potentially enable escalation of…

  • CVE-2022-43456MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) RST software before versions 16.8.5.1014.5, 17.11.3.1010.2, 18.7.6.1011.2 and 19.5.2.1049.5 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-25864MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) oneMKL software before version 2022.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-28080MedMay 30, 2023
    risk 0.44cvss 6.7epss 0.00

    PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains DLL Hijacking Vulnerabilities. A regular user (non-admin) can exploit these issues to potentially escalate privileges and execute arbitrary code in the context of NT AUTHORITY\SYSTEM.

  • CVE-2023-31197MedMay 12, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in the Intel(R) Trace Analyzer and Collector before version 2020 update 3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-27386MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) Pathfinder for RISC-V software may allow an authenticated user to potentially enable escalation of privilege via local access.