Weaknesses of type CWE-427

897 results

Caminho de busca ou elemento não controlado

A aplicação procura por bibliotecas, configurações ou outros recursos em diretórios sem validar adequadamente quais caminhos ela está usando, permitindo que um atacante injete uma versão maliciosa em um local que será encontrado primeiro. Isso acontece porque a ordem ou composição do caminho de busca não é explicitamente controlada.

Example

Um programa Java com classpath que inclui o diretório atual (.) antes de caminhos do sistema; um atacante coloca uma classe maliciosa no diretório de trabalho e ela é carregada em vez da legítima. Ou um script que procura por um arquivo de configuração em múltiplas pastas sem especificar o caminho absoluto, sendo enganado por um arquivo plantado em /tmp.

How to mitigate

Use caminhos absolutos explícitos em vez de relativos; remova diretórios inseguros (como o atual) do caminho de busca; valide a origem e integridade de recursos carregados (checksums, assinaturas); implemente listas de permitidos para diretórios confiáveis.

CVE-2022-26374HIGHUncontrolled search path in the installation binaries for Intel(R) SEAPI all versions may allow an authenticated user to potentially enable EPSS 0.2%CVE-2022-28696HIGHUncontrolled search path in the Intel(R) Distribution for Python before version 2022.0.3 may allow an authenticated user to potentially enabEPSS 0.2%CVE-2022-25841HIGHUncontrolled search path elements in the Intel(R) Datacenter Group Event Android application, all versions, may allow an authenticated user EPSS 0.2%CVE-2026-4546HIGHFlos Freeware Notepad2 TextShaping.dll uncontrolled search pathEPSS 0.2%CVE-2025-49571HIGHSubstance3D - Modeler | Uncontrolled Search Path Element (CWE-427)EPSS 0.2%CVE-2022-32972HIGHInfoblox BloxOne Endpoint for Windows through 2.2.7 allows DLL injection that can result in local privilege escalation.EPSS 0.2%CVE-2022-27180MEDIUMUncontrolled search path in the Intel(R) MacCPUID software before version 3.2 may allow an authenticated user to potentially enable escalatiEPSS 0.2%CVE-2024-7061MEDIUMOkta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows vEPSS 0.2%CVE-2025-1131HIGHAsterisk Unsafe Shell Sourcing in safe_asterisk Leads to Local Privilege EscalationEPSS 0.2%CVE-2023-32646MEDIUMUncontrolled search path element in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enaEPSS 0.2%CVE-2023-0213HIGHLocal Elevation of Privilege in M-FilesEPSS 0.2%CVE-2023-3662HIGHCODESYS: Vulnerability in CODESYS Development System allows for execution of binariesEPSS 0.2%CVE-2023-31016HIGHCVEEPSS 0.2%CVE-2022-41796HIGHUntrusted search path vulnerability in the installer of Content Transfer (for Windows) Ver.1.3 and prior allows an attacker to gain privilegEPSS 0.2%CVE-2021-3423HIGHPrivilege escalation in Bitdefender GravityZone Business SecurityEPSS 0.2%CVE-2025-4539HIGHHainan ToDesk DLL File Parser profapi.dll uncontrolled search pathEPSS 0.2%CVE-2024-10093HIGHVSO ConvertXtoDvd ConvertXtoDvd.exe uncontrolled search pathEPSS 0.2%CVE-2026-0487HIGHDLL Hijacking vulnerability in SAProuter on Microsoft WindowsEPSS 0.2%CVE-2023-6338HIGHUncontrolled search path vulnerabilities were reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local aEPSS 0.2%CVE-2023-33874MEDIUMUncontrolled search path in some Intel(R) NUC 12 Pro Kits & Mini PCs - NUC12WS Intel(R) HID Event Filter Driver installation software beforeEPSS 0.2%