Weaknesses of type CWE-426

322 results

Caminho de busca não confiável

Ocorre quando a aplicação busca por bibliotecas, executáveis ou arquivos em diretórios cuja ordem ou conteúdo pode ser controlado por um atacante. Se um diretório não confiável vem antes de um diretório legítimo no PATH (ou em lógica de busca customizada), o atacante injeta um arquivo malicioso com o mesmo nome para ser carregado no lugar do original.

Example

Um software Windows busca 'config.dll' primeiro no diretório atual antes de procurar em System32. Um atacante coloca uma DLL maliciosa com esse nome na pasta de trabalho; quando o software executa, carrega a versão maliciosa e compromete a máquina.

How to mitigate

Especifique sempre caminhos absolutos completos ao carregar bibliotecas e executáveis, evitando buscas dinâmicas em PATH. Em Unix/Linux, remova ou coloque o diretório atual (.) ao final do PATH, nunca no início; no Windows, configure DLL search order e use mecanismos como SetDllDirectory para restringir onde as DLLs são procuradas.

CVE-2023-27759HIGHAn issue found in Wondershare Technology Co, Ltd Edrawmind v.10.0.6 allows a remote attacker to executea arbitrary commands via the WindowsCEPSS 0.4%CVE-2026-45772NONETurborepo: Unexpected local code execution during Yarn Berry detectionEPSS 0.4%CVE-2023-23618HIGHgitk can inadvertently call executables in the worktreeEPSS 0.4%CVE-2024-28133HIGHPHOENIX CONTACT: Privilege escalation in CHARX Series EPSS 0.4%CVE-2023-29299MEDIUMAdobe Acrobat Reader Untrusted Search Path Application denial-of-serviceEPSS 0.4%CVE-2025-12819HIGHUntrusted search path in auth_query connection in PgBouncerEPSS 0.4%CVE-2022-36070HIGHPoetry's Untrusted Search Path can lead to Local Code Execution on WindowsEPSS 0.4%CVE-2025-49124HIGHApache Tomcat: exe side-loading via icalcs.exe in Tomcat installer for WindowsEPSS 0.4%CVE-2023-1521HIGHLocal Privilege Escalation in sccacheEPSS 0.4%CVE-2023-26358HIGHAdobe Creative Cloud AdobeExtensionService.exe local privilege escalation vulnerabilityEPSS 0.4%CVE-2023-22743HIGHGit for Windows' installer is susceptible to DLL side loading attacksEPSS 0.4%CVE-2024-47422HIGHAdobe Framemaker | Untrusted Search Path (CWE-426)EPSS 0.4%CVE-2019-17100MEDIUMUntrusted Search Path vulnerability in Bitdefender Total Security 2020 (VA-5895)EPSS 0.3%CVE-2020-6023—Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to escalate privileges while restoring files in Anti-Ransomware.EPSS 0.3%CVE-2024-41865HIGHAdobe Dimension Untrusted Search Path lead to load malicious DLL swift.dllEPSS 0.3%CVE-2024-20754HIGHLightroom Desktop | Untrusted Search Path (CWE-426)EPSS 0.3%CVE-2022-31253HIGHopenldap2: /usr/lib/openldap/start allows ldap user/group to recursively chown arbitrary directory trees to itselfEPSS 0.3%CVE-2021-3305HIGHBeijing Feishu Technology Co., Ltd Feishu v3.40.3 was discovered to contain an untrusted search path vulnerability.EPSS 0.3%CVE-2024-9325HIGHIntelbras InControl incontrol-service-watchdog.exe unquoted search pathEPSS 0.3%CVE-2024-38305HIGHDell SupportAssist for Home PCs Installer exe version 4.0.3 contains a privilege escalation vulnerability in the installer. A local low-privEPSS 0.3%