VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,213)

page 6 of 61
  • CVE-2025-56383HigSep 26, 2025
    risk 0.55cvss 8.4epss 0.00

    Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to execute malicious code. NOTE: this is disputed by multiple parties because the behavior only occurs when a user installs the product into a directory tree that allows write access by…

  • CVE-2024-13976HigJul 25, 2025
    risk 0.55cvss epss 0.00

    A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance updates, an attacker with local access may exploit uncontrolled search path or DLL loading behavior to execute arbitrary code…

  • CVE-2025-27997HigMay 21, 2025
    risk 0.55cvss 8.4epss 0.00

    An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script or executable into the C:\ProgramData directory.

  • CVE-2024-11859HigApr 7, 2025
    risk 0.55cvss epss 0.02

    DLL Search Order Hijacking vulnerability potentially allowed an attacker with administrator privileges to load a malicious dynamic-link library and execute its code.

  • CVE-2024-55898HigFeb 24, 2025
    risk 0.55cvss 8.5epss 0.00

    IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user with the capability to compile or restore a program to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege.

  • CVE-2024-2658HigJan 30, 2025
    risk 0.55cvss epss 0.00

    A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and…

  • CVE-2024-25050HigApr 28, 2024
    risk 0.55cvss 8.4epss 0.00

    IBM i 7.2, 7.3, 7.4, 7.5 and IBM Rational Development Studio for i 7.2, 7.3, 7.4, 7.5 networking and compiler infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with…

  • CVE-2024-22346HigMar 14, 2024
    risk 0.55cvss 8.4epss 0.00

    Db2 for IBM i 7.2, 7.3, 7.4, and 7.5 infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege. IBM X-Force ID: 280203.

  • CVE-2023-35897HigOct 6, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0 could allow a local user to execute arbitrary code on the system using a specially crafted file, caused by a DLL hijacking flaw. IBM X-Force ID: 259246.

  • CVE-2020-25244HigApr 22, 2021
    risk 0.55cvss 8.4epss 0.00

    A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). The software insecurely loads libraries which makes it vulnerable to DLL hijacking. Successful exploitation by a local attacker could lead to a takeover of the system where the software is installed.

  • CVE-2019-9491HigOct 21, 2019
    risk 0.55cvss 7.8epss 0.13

    Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed.

  • CVE-2017-7884HigJun 16, 2017
    risk 0.55cvss 8.4epss 0.00

    In Adam Kropelin adk0212 APC UPS Daemon through 3.14.14, the default installation of APCUPSD allows a local authenticated, but unprivileged, user to run arbitrary code with elevated privileges by replacing the service executable apcupsd.exe with a malicious executable that will…

  • CVE-2022-47636HigAug 10, 2023
    risk 0.54cvss 7.8epss 0.01

    A DLL hijacking vulnerability has been discovered in OutSystems Service Studio 11 11.53.30 build 61739. When a user open a .oml file (OutSystems Modeling Language), the application will load the following DLLs from the same directory av_libGLESv2.dll, libcef.DLL, user32.dll, and…

  • CVE-2021-28570HigJun 28, 2021
    risk 0.54cvss 8.3epss 0.02

    Adobe After Effects version 18.1 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An unauthenticated attacker could exploit this to to plant custom binaries and execute them with System permissions. Exploitation of this issue requires user…

  • CVE-2019-5526HigMay 15, 2019
    risk 0.54cvss 7.8epss 0.09

    VMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are improperly loaded by the application. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to administrator on a…

  • CVE-2017-16777HigNov 16, 2017
    risk 0.54cvss 7.8epss 0.01

    If HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.3 is installed but VMware Fusion is not, a local attacker can create a fake application directory and exploit the suid sudo helper in order to escalate to root.

  • CVE-2017-12579HigOct 19, 2017
    risk 0.54cvss 7.8epss 0.01

    An insecure suid wrapper binary in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 4.0.24 and earlier allows a non-root user to obtain a root shell.

  • CVE-2014-8393HigAug 29, 2017
    risk 0.54cvss 7.8epss 0.08

    DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel PDF Fusion.

  • CVE-2017-12653HigAug 7, 2017
    risk 0.54cvss 7.8epss 0.02

    360 Total Security 9.0.0.1202 before 2017-07-07 allows Privilege Escalation via a Trojan horse Shcore.dll file in any directory in the PATH, as demonstrated by the C:\Python27 directory.

  • CVE-2025-23358HigNov 4, 2025
    risk 0.53cvss 8.2epss 0.00

    NVIDIA NVApp for Windows contains a vulnerability in the installer, where a local attacker can cause a search path element issue. A successful exploit of this vulnerability might lead to code execution and escalation of privileges.