VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,213)

page 56 of 61
  • CVE-2025-7427MedJul 22, 2025
    risk 0.38cvss 5.9epss 0.00

    Uncontrolled Search Path Element in Arm Development Studio before 2025 may allow an attacker to perform a DLL hijacking attack. Successful exploitation could lead to local arbitrary code execution in the context of the user running Arm Development Studio.

  • CVE-2023-0400MedFeb 2, 2023
    risk 0.38cvss 5.9epss 0.00

    The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP controls when uploading sensitive data from a mapped drive into a web email client. Loading from a local driver was correctly prevented.…

  • CVE-2022-28541MedApr 11, 2022
    risk 0.38cvss 5.9epss 0.00

    Uncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute arbitrary code as Samsung Update permission.

  • CVE-2020-7358MedSep 18, 2020
    risk 0.38cvss 5.8epss 0.00

    In AppSpider installer versions prior to 7.2.126, the AppSpider installer calls an executable which can be placed in the appropriate directory by an attacker with access to the local machine. This would prevent the installer from distinguishing between a valid executable called…

  • CVE-2019-3613MedJun 10, 2020
    risk 0.38cvss 5.9epss 0.00

    DLL Search Order Hijacking vulnerability in McAfee Agent (MA) prior to 5.6.4 allows attackers with local access to execute arbitrary code via execution from a compromised folder.

  • CVE-2026-44406MedMay 7, 2026
    risk 0.37cvss 5.7epss 0.00

    ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.contains a DLL hijacking vulnerability;…

  • CVE-2026-25129MedJan 30, 2026
    risk 0.37cvss 6.7epss 0.00

    PsySH is a runtime developer console, interactive debugger, and REPL for PHP. Prior to versions 0.11.23 and 0.12.19, PsySH automatically loads and executes a `.psysh.php` file from the Current Working Directory (CWD) on startup. If an attacker can write to a directory that a…

  • CVE-2025-29817MedApr 15, 2025
    risk 0.37cvss 5.7epss 0.01

    Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network.

  • CVE-2025-26624MedFeb 18, 2025
    risk 0.37cvss epss 0.00

    Rufus is a utility that helps format and create bootable USB flash drives. A DLL hijacking vulnerability in Rufus 4.6.2208 and earlier versions allows an attacker loading and executing a malicious DLL with escalated privileges (since the executable has been granted higher…

  • CVE-2024-40644MedJul 18, 2024
    risk 0.37cvss 6.8epss 0.00

    gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. `gix-path` can be tricked into running another `git.exe` placed in an untrusted location by a limited user account on Windows systems. Windows permits limited user accounts without administrative…

  • CVE-2020-27348MedDec 4, 2020
    risk 0.37cvss 6.8epss 0.01

    In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a malicious snap to gain code execution within the context of another snap if both plug the home interface or similar. This issue affects snapcraft versions prior to…

  • CVE-2026-40004MedMay 7, 2026
    risk 0.36cvss 5.5epss 0.00

    There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execute arbitrary code locally and escalate privileges.

  • CVE-2026-26099MedFeb 20, 2026
    risk 0.36cvss 5.5epss 0.00

    Uncontrolled Search Path Element in Owl opds 2.2.0.4 allows Leveraging/Manipulating Configuration File Search Paths via a crafted network request.

  • CVE-2026-26098MedFeb 20, 2026
    risk 0.36cvss 5.5epss 0.00

    Uncontrolled Search Path Element in Owl opds 2.2.0.4 allows Leveraging/Manipulating Configuration File Search Paths via a crafted network request.

  • CVE-2026-26097MedFeb 20, 2026
    risk 0.36cvss 5.5epss 0.00

    Uncontrolled Search Path Element in Owl opds 2.2.0.4 allows Leveraging/Manipulating Configuration File Search Paths via a crafted network request.

  • CVE-2024-44168MedSep 17, 2024
    risk 0.36cvss 5.5epss 0.00

    A library injection issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An app may be able to modify protected parts of the file system.

  • CVE-2024-7061MedAug 7, 2024
    risk 0.36cvss 5.5epss 0.00

    Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows version 5.0.2. To remediate this vulnerability, upgrade to 5.0.2 or greater.

  • CVE-2023-4936MedOct 11, 2023
    risk 0.36cvss 5.5epss 0.00

    It is possible to sideload a compromised DLL during the installation at elevated privilege.

  • CVE-2023-24578MedMar 13, 2023
    risk 0.36cvss 5.5epss 0.00

    McAfee Total Protection prior to 16.0.49 allows attackers to elevate user privileges due to DLL sideloading. This could enable a user with lower privileges to execute unauthorized tasks.

  • CVE-2022-36314MedDec 22, 2022
    risk 0.36cvss 5.5epss 0.00

    When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system.This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability…