CWE-427
Uncontrolled Search Path Element
Description
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-38 · CAPEC-471
CVEs mapped to this weakness (1,213)
page 56 of 61| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-7427 | Med | 0.38 | 5.9 | 0.00 | Jul 22, 2025 | Uncontrolled Search Path Element in Arm Development Studio before 2025 may allow an attacker to perform a DLL hijacking attack. Successful exploitation could lead to local arbitrary code execution in the context of the user running Arm Development Studio. | ||
| CVE-2023-0400 | Med | 0.38 | 5.9 | 0.00 | Feb 2, 2023 | The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP controls when uploading sensitive data from a mapped drive into a web email client. Loading from a local driver was correctly prevented.… | ||
| CVE-2022-28541 | Med | 0.38 | 5.9 | 0.00 | Apr 11, 2022 | Uncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute arbitrary code as Samsung Update permission. | ||
| CVE-2020-7358 | Med | 0.38 | 5.8 | 0.00 | Sep 18, 2020 | In AppSpider installer versions prior to 7.2.126, the AppSpider installer calls an executable which can be placed in the appropriate directory by an attacker with access to the local machine. This would prevent the installer from distinguishing between a valid executable called… | ||
| CVE-2019-3613 | Med | 0.38 | 5.9 | 0.00 | Jun 10, 2020 | DLL Search Order Hijacking vulnerability in McAfee Agent (MA) prior to 5.6.4 allows attackers with local access to execute arbitrary code via execution from a compromised folder. | ||
| CVE-2026-44406 | Med | 0.37 | 5.7 | 0.00 | May 7, 2026 | ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.contains a DLL hijacking vulnerability;… | ||
| CVE-2026-25129 | Med | 0.37 | 6.7 | 0.00 | Jan 30, 2026 | PsySH is a runtime developer console, interactive debugger, and REPL for PHP. Prior to versions 0.11.23 and 0.12.19, PsySH automatically loads and executes a `.psysh.php` file from the Current Working Directory (CWD) on startup. If an attacker can write to a directory that a… | ||
| CVE-2025-29817 | Med | 0.37 | 5.7 | 0.01 | Apr 15, 2025 | Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-26624 | Med | 0.37 | — | 0.00 | Feb 18, 2025 | Rufus is a utility that helps format and create bootable USB flash drives. A DLL hijacking vulnerability in Rufus 4.6.2208 and earlier versions allows an attacker loading and executing a malicious DLL with escalated privileges (since the executable has been granted higher… | ||
| CVE-2024-40644 | Med | 0.37 | 6.8 | 0.00 | Jul 18, 2024 | gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. `gix-path` can be tricked into running another `git.exe` placed in an untrusted location by a limited user account on Windows systems. Windows permits limited user accounts without administrative… | ||
| CVE-2020-27348 | Med | 0.37 | 6.8 | 0.01 | Dec 4, 2020 | In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a malicious snap to gain code execution within the context of another snap if both plug the home interface or similar. This issue affects snapcraft versions prior to… | ||
| CVE-2026-40004 | Med | 0.36 | 5.5 | 0.00 | May 7, 2026 | There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execute arbitrary code locally and escalate privileges. | ||
| CVE-2026-26099 | Med | 0.36 | 5.5 | 0.00 | Feb 20, 2026 | Uncontrolled Search Path Element in Owl opds 2.2.0.4 allows Leveraging/Manipulating Configuration File Search Paths via a crafted network request. | ||
| CVE-2026-26098 | Med | 0.36 | 5.5 | 0.00 | Feb 20, 2026 | Uncontrolled Search Path Element in Owl opds 2.2.0.4 allows Leveraging/Manipulating Configuration File Search Paths via a crafted network request. | ||
| CVE-2026-26097 | Med | 0.36 | 5.5 | 0.00 | Feb 20, 2026 | Uncontrolled Search Path Element in Owl opds 2.2.0.4 allows Leveraging/Manipulating Configuration File Search Paths via a crafted network request. | ||
| CVE-2024-44168 | Med | 0.36 | 5.5 | 0.00 | Sep 17, 2024 | A library injection issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An app may be able to modify protected parts of the file system. | ||
| CVE-2024-7061 | Med | 0.36 | 5.5 | 0.00 | Aug 7, 2024 | Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows version 5.0.2. To remediate this vulnerability, upgrade to 5.0.2 or greater. | ||
| CVE-2023-4936 | Med | 0.36 | 5.5 | 0.00 | Oct 11, 2023 | It is possible to sideload a compromised DLL during the installation at elevated privilege. | ||
| CVE-2023-24578 | Med | 0.36 | 5.5 | 0.00 | Mar 13, 2023 | McAfee Total Protection prior to 16.0.49 allows attackers to elevate user privileges due to DLL sideloading. This could enable a user with lower privileges to execute unauthorized tasks. | ||
| CVE-2022-36314 | Med | 0.36 | 5.5 | 0.00 | Dec 22, 2022 | When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system.This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability… |
- risk 0.38cvss 5.9epss 0.00
Uncontrolled Search Path Element in Arm Development Studio before 2025 may allow an attacker to perform a DLL hijacking attack. Successful exploitation could lead to local arbitrary code execution in the context of the user running Arm Development Studio.
- risk 0.38cvss 5.9epss 0.00
The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP controls when uploading sensitive data from a mapped drive into a web email client. Loading from a local driver was correctly prevented.…
- risk 0.38cvss 5.9epss 0.00
Uncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute arbitrary code as Samsung Update permission.
- risk 0.38cvss 5.8epss 0.00
In AppSpider installer versions prior to 7.2.126, the AppSpider installer calls an executable which can be placed in the appropriate directory by an attacker with access to the local machine. This would prevent the installer from distinguishing between a valid executable called…
- risk 0.38cvss 5.9epss 0.00
DLL Search Order Hijacking vulnerability in McAfee Agent (MA) prior to 5.6.4 allows attackers with local access to execute arbitrary code via execution from a compromised folder.
- risk 0.37cvss 5.7epss 0.00
ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.contains a DLL hijacking vulnerability;…
- risk 0.37cvss 6.7epss 0.00
PsySH is a runtime developer console, interactive debugger, and REPL for PHP. Prior to versions 0.11.23 and 0.12.19, PsySH automatically loads and executes a `.psysh.php` file from the Current Working Directory (CWD) on startup. If an attacker can write to a directory that a…
- risk 0.37cvss 5.7epss 0.01
Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network.
- risk 0.37cvss —epss 0.00
Rufus is a utility that helps format and create bootable USB flash drives. A DLL hijacking vulnerability in Rufus 4.6.2208 and earlier versions allows an attacker loading and executing a malicious DLL with escalated privileges (since the executable has been granted higher…
- risk 0.37cvss 6.8epss 0.00
gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. `gix-path` can be tricked into running another `git.exe` placed in an untrusted location by a limited user account on Windows systems. Windows permits limited user accounts without administrative…
- risk 0.37cvss 6.8epss 0.01
In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a malicious snap to gain code execution within the context of another snap if both plug the home interface or similar. This issue affects snapcraft versions prior to…
- risk 0.36cvss 5.5epss 0.00
There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execute arbitrary code locally and escalate privileges.
- risk 0.36cvss 5.5epss 0.00
Uncontrolled Search Path Element in Owl opds 2.2.0.4 allows Leveraging/Manipulating Configuration File Search Paths via a crafted network request.
- risk 0.36cvss 5.5epss 0.00
Uncontrolled Search Path Element in Owl opds 2.2.0.4 allows Leveraging/Manipulating Configuration File Search Paths via a crafted network request.
- risk 0.36cvss 5.5epss 0.00
Uncontrolled Search Path Element in Owl opds 2.2.0.4 allows Leveraging/Manipulating Configuration File Search Paths via a crafted network request.
- risk 0.36cvss 5.5epss 0.00
A library injection issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An app may be able to modify protected parts of the file system.
- risk 0.36cvss 5.5epss 0.00
Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows version 5.0.2. To remediate this vulnerability, upgrade to 5.0.2 or greater.
- risk 0.36cvss 5.5epss 0.00
It is possible to sideload a compromised DLL during the installation at elevated privilege.
- risk 0.36cvss 5.5epss 0.00
McAfee Total Protection prior to 16.0.49 allows attackers to elevate user privileges due to DLL sideloading. This could enable a user with lower privileges to execute unauthorized tasks.
- risk 0.36cvss 5.5epss 0.00
When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system.This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability…