VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,213)

page 52 of 61
  • CVE-2022-28247MedMay 11, 2022
    risk 0.44cvss 6.7epss 0.00

    Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an uncontrolled search path vulnerability that could lead to local privilege escalation. Exploitation of this issue requires user interaction in that a…

  • CVE-2022-0025MedMay 11, 2022
    risk 0.44cvss 6.7epss 0.00

    A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local user with file creation privilege in the Windows root directory (such as C:\) to execute a program with elevated privileges. This…

  • CVE-2020-25182MedMar 18, 2022
    risk 0.44cvss 6.7epss 0.00

    Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries. Uncontrolled loading of dynamic libraries could allow a local, unauthenticated attacker to execute arbitrary code. This vulnerability only affects ISaGRAF Runtime when…

  • CVE-2022-22943MedMar 3, 2022
    risk 0.44cvss 6.7epss 0.01

    VMware Tools for Windows (11.x.y and 10.x.y prior to 12.0.0) contains an uncontrolled search path vulnerability. A malicious actor with local administrative privileges in the Windows guest OS, where VMware Tools is installed, may be able to execute code with system privileges in…

  • CVE-2021-0169MedFeb 9, 2022
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled Search Path Element in software for Intel(R) PROSet/Wireless Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2021-36753HigJul 15, 2021
    risk 0.44cvss 7.8epss 0.00

    sharkdp BAT before 0.18.2 executes less.exe from the current working directory.

  • CVE-2021-35957MedJul 13, 2021
    risk 0.44cvss 6.7epss 0.00

    Stormshield Endpoint Security Evolution 2.0.0 through 2.0.2 does not accomplish the intended defense against local administrators who can replace the Visual C++ runtime DLLs (in %WINDIR%\system32) with malicious ones.

  • CVE-2021-36376HigJul 13, 2021
    risk 0.44cvss 7.8epss 0.00

    dandavison delta before 0.8.3 on Windows resolves an executable's pathname as a relative path from the current directory.

  • CVE-2020-5419MedAug 31, 2020
    risk 0.44cvss 6.7epss 0.00

    RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation directory and local access on Windows could carry out a local…

  • CVE-2020-15596MedAug 12, 2020
    risk 0.44cvss 6.7epss 0.00

    The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on various Dell, HP, and Lenovo laptops, allows attackers to conduct Path Disclosure attacks via a "fake" DLL file.

  • CVE-2019-14600MedJan 17, 2020
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in the installer for Intel(R) SNMP Subagent Stand-Alone for Windows* may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2019-12758MedNov 15, 2019
    risk 0.44cvss 6.7epss 0.01

    Symantec Endpoint Protection, prior to 14.2 RU2, may be susceptible to an unsigned code execution vulnerability, which may allow an individual to execute code without a resident proper digital signature.

  • CVE-2019-6333MedOct 11, 2019
    risk 0.44cvss 6.7epss 0.01

    A potential security vulnerability has been identified with certain versions of HP Touchpoint Analytics prior to version 4.1.4.2827. This vulnerability may allow a local attacker with administrative privileges to execute arbitrary code via an HP Touchpoint Analytics system…

  • CVE-2019-3726MedSep 24, 2019
    risk 0.44cvss 6.7epss 0.00

    An Uncontrolled Search Path Vulnerability is applicable to the following: Dell Update Package (DUP) Framework file versions prior to 19.1.0.413, and Framework file versions prior to 103.4.6.69 used in Dell EMC Servers. Dell Update Package (DUP) Framework file versions prior to…

  • CVE-2019-14242MedJul 30, 2019
    risk 0.44cvss 6.7epss 0.01

    An issue was discovered in Bitdefender products for Windows (Bitdefender Endpoint Security Tool versions prior to 6.6.8.115; and Bitdefender Antivirus Plus, Bitdefender Internet Security, and Bitdefender Total Security versions prior to 23.0.24.120) that can lead to local code…

  • CVE-2019-5676MedMay 10, 2019
    risk 0.44cvss 6.7epss 0.01

    NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), leading to escalation of…

  • CVE-2017-12313MedNov 16, 2017
    risk 0.44cvss 6.7epss 0.01

    An untrusted search path (aka DLL Preload) vulnerability in the Cisco Network Academy Packet Tracer software could allow an authenticated, local attacker to execute arbitrary code via DLL hijacking if a local user with administrative privileges executes the installer in the…

  • CVE-2017-6417MedMar 21, 2017
    risk 0.44cvss 6.7epss 0.01

    Code injection vulnerability in Avira Total Security Suite 15.0 (and earlier), Optimization Suite 15.0 (and earlier), Internet Security Suite 15.0 (and earlier), and Free Security Suite 15.0 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject…

  • CVE-2017-5567MedMar 21, 2017
    risk 0.44cvss 6.7epss 0.01

    Code injection vulnerability in Avast Premier 12.3 (and earlier), Internet Security 12.3 (and earlier), Pro Antivirus 12.3 (and earlier), and Free Antivirus 12.3 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full…

  • CVE-2017-5566MedMar 21, 2017
    risk 0.44cvss 6.7epss 0.01

    Code injection vulnerability in AVG Ultimate 17.1 (and earlier), AVG Internet Security 17.1 (and earlier), and AVG AntiVirus FREE 17.1 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any AVG process via…