Weaknesses of type CWE-426

322 results

Caminho de busca não confiável

Ocorre quando a aplicação busca por bibliotecas, executáveis ou arquivos em diretórios cuja ordem ou conteúdo pode ser controlado por um atacante. Se um diretório não confiável vem antes de um diretório legítimo no PATH (ou em lógica de busca customizada), o atacante injeta um arquivo malicioso com o mesmo nome para ser carregado no lugar do original.

Example

Um software Windows busca 'config.dll' primeiro no diretório atual antes de procurar em System32. Um atacante coloca uma DLL maliciosa com esse nome na pasta de trabalho; quando o software executa, carrega a versão maliciosa e compromete a máquina.

How to mitigate

Especifique sempre caminhos absolutos completos ao carregar bibliotecas e executáveis, evitando buscas dinâmicas em PATH. Em Unix/Linux, remova ou coloque o diretório atual (.) ao final do PATH, nunca no início; no Windows, configure DLL search order e use mecanismos como SetDllDirectory para restringir onde as DLLs são procuradas.

CVE-2024-58250CRITICALThe passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges.EPSS 0.2%CVE-2026-4962HIGHUltraVNC Service version.dll uncontrolled search pathEPSS 0.2%CVE-2021-26738HIGHPrivilege Escalation for ZCC macOS via PATH VariableEPSS 0.2%CVE-2025-27167HIGHIllustrator | Untrusted Search Path (CWE-426)EPSS 0.2%CVE-2026-48395HIGHBridge | Untrusted Search Path (CWE-426)EPSS 0.2%CVE-2026-48287HIGHCAI Content Credentials | Untrusted Search Path (CWE-426)EPSS 0.2%CVE-2021-21562MEDIUMDell EMC PowerScale OneFS contains an untrusted search path vulnerability. This vulnerability allows a user with (ISI_PRIV_LOGIN_SSH or ISI_EPSS 0.2%CVE-2026-33156HIGHDLL Sideloading in ScreenToGifEPSS 0.2%CVE-2026-23512HIGHSumatraPDF has an Untrusted Search Path in sumatrapdf/src/AppTools.cppEPSS 0.2%CVE-2024-47906HIGHExcessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before versiEPSS 0.2%CVE-2024-22410LOWBinary Planting Attack on Windows Platforms in CreditcoinEPSS 0.2%CVE-2026-47648HIGHWindows Storage Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2026-24070HIGHLocal Privilege Escalation via DYLIB Injection in Native Instruments Native AccessEPSS 0.2%CVE-2025-1068HIGHThere is a code injection vulnerability in Esri ArcGIS AllSourceEPSS 0.2%CVE-2026-4546HIGHFlos Freeware Notepad2 TextShaping.dll uncontrolled search pathEPSS 0.2%CVE-2025-0145MEDIUMZoom Workplace Apps for Windows - Untrusted Search PathEPSS 0.2%CVE-2025-4539HIGHHainan ToDesk DLL File Parser profapi.dll uncontrolled search pathEPSS 0.2%CVE-2023-39202LOWUntrusted search path in Zoom Rooms Client for Windows and Zoom VDI Client may allow a privileged user to conduct a denial of service via loEPSS 0.2%CVE-2026-40156HIGHPraisonAI Affected by Implicit Execution of Arbitrary Code via Automatic `tools.py` LoadingEPSS 0.2%CVE-2025-5335HIGHPrivilege Ecalation due to Untrusted Search Path VulnerabilityEPSS 0.2%