VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,213)

page 50 of 61
  • CVE-2023-22355MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-43474MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for the DSP Builder software installer before version 22.4 for Intel(R) FPGAs Pro Edition may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-41998MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-41982MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-41693MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in the Intel(R) Quartus(R) Prime Pro edition software before version 22.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-41628MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1.44 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-38101MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) NUC Chaco Canyon BIOS update software before version iFlashV Windows 5.13.00.2105 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-34848MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-32576MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in the Intel(R) Unite(R) Plugin SDK before version 4.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-21162MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for the Intel(R) HDMI Firmware Update tool for NUC before version 1.79.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-28140MedApr 18, 2023
    risk 0.44cvss 6.7epss 0.00

    An Executable Hijacking condition exists in the Qualys Cloud Agent for Windows platform in versions before 4.5.3.1. Attackers may load a malicious copy of a Dependency Link Library (DLL) via a local attack vector instead of the DLL that the application was expecting, when…

  • CVE-2023-29187MedApr 11, 2023
    risk 0.44cvss 6.7epss 0.00

    A Windows user with basic user authorization can exploit a DLL hijacking attack in SapSetup (Software Installation Program) - version 9.0, resulting in a privilege escalation running code as administrator of the very same Windows PC. A successful attack depends on various…

  • CVE-2022-48223MedApr 4, 2023
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During SDK repair, certutil.exe is called by the Acuant installer to repair certificates. This call is vulnerable to DLL hijacking due to a race condition and insecure permissions on the executing directory.

  • CVE-2023-25147MedMar 10, 2023
    risk 0.44cvss 6.7epss 0.00

    An issue in the Trend Micro Apex One agent could allow an attacker who has previously acquired administrative rights via other means to bypass the protection by using a specifically crafted DLL during a specific update process. Please note: an attacker must first obtain…

  • CVE-2022-41314MedFeb 16, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) Network Adapter installer software may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-37340MedFeb 16, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) QAT drivers for Windows before version 1.6 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-37329MedFeb 16, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) Quartus(R) Prime Pro and Standard Edition software may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-36398MedFeb 16, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in the Intel(R) Battery Life Diagnostic Tool software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-26512MedFeb 16, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in the Intel(R) FPGA Add-on for Intel(R) oneAPI Base Toolkit before version 2022.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-26425MedFeb 16, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in the Intel(R) oneAPI Collective Communications Library (oneCCL) before version 2021.6 for Intel(R) oneAPI Base Toolkit may allow an authenticated user to potentially enable escalation of privilege via local access.