Weaknesses of type CWE-427

897 results

Caminho de busca ou elemento não controlado

A aplicação procura por bibliotecas, configurações ou outros recursos em diretórios sem validar adequadamente quais caminhos ela está usando, permitindo que um atacante injete uma versão maliciosa em um local que será encontrado primeiro. Isso acontece porque a ordem ou composição do caminho de busca não é explicitamente controlada.

Example

Um programa Java com classpath que inclui o diretório atual (.) antes de caminhos do sistema; um atacante coloca uma classe maliciosa no diretório de trabalho e ela é carregada em vez da legítima. Ou um script que procura por um arquivo de configuração em múltiplas pastas sem especificar o caminho absoluto, sendo enganado por um arquivo plantado em /tmp.

How to mitigate

Use caminhos absolutos explícitos em vez de relativos; remova diretórios inseguros (como o atual) do caminho de busca; valide a origem e integridade de recursos carregados (checksums, assinaturas); implemente listas de permitidos para diretórios confiáveis.

CVE-2023-45320MEDIUMUncontrolled search path element in some Intel(R) VTune(TM) Profiler software before version 2024.0 may allow an authenticated user to potenEPSS 0.2%CVE-2025-11178HIGHLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before builEPSS 0.2%CVE-2024-57964HIGHInsecure Loading of Dynamic Link Libraries in HVAC Energy Saving ProgramEPSS 0.2%CVE-2025-57716MEDIUMAn Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versioEPSS 0.2%CVE-2023-28080MEDIUM PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains DLL Hijacking Vulnerabilities. A regular user (non-admin) can exploit these issues EPSS 0.2%CVE-2026-24317MEDIUMDLL Hijacking vulnerability in SAP GUI for Windows with active GuiXTEPSS 0.2%CVE-2025-48496MEDIUMEmerson ValveLink Products Uncontrolled Search Path ElementEPSS 0.2%CVE-2024-57963HIGHInsecure Loading of Dynamic Link Libraries in USB-CONVERTERCABLE DRIVEREPSS 0.2%CVE-2025-5470HIGHDylib Hijacking in Yandex DiskEPSS 0.2%CVE-2024-37024MEDIUMUncontrolled search path for some ACAT software maintained by Intel(R) for Windows before version 3.11.0 may allow an authenticated user to EPSS 0.2%CVE-2024-34164MEDIUMUncontrolled search path element in some Intel(R) MAS software before version 2.5 may allow an authenticated user to potentially enable escaEPSS 0.2%CVE-2024-31407MEDIUMUncontrolled search path in some Intel(R) High Level Synthesis Compiler software for Intel(R) Quartus(R) Prime Pro Edition Software before vEPSS 0.2%CVE-2024-23312MEDIUMUncontrolled search path for some Intel(R) Binary Configuration Tool software for Windows before version 3.4.5 may allow an authenticated usEPSS 0.2%CVE-2026-6958HIGHAcunetix 25.11.251107123 Local Privilege Escalation via wvsc.exeEPSS 0.2%CVE-2024-28950MEDIUMUncontrolled search path for some Intel(R) oneAPI Math Kernel Library software for Windows before version 2024.2 may allow an authenticated EPSS 0.2%CVE-2026-6788HIGHUncontrolled search path in PluginLauncher allows SYSTEM code execution in WatchGuard AgentEPSS 0.2%CVE-2024-34028MEDIUMUncontrolled search path in some Intel(R) Graphics Offline Compiler for OpenCL(TM) Code software for Windows before version 2024.1.0.142, grEPSS 0.2%CVE-2024-35245MEDIUMUncontrolled search path element in some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.60 may allow an authenticated EPSS 0.2%CVE-2024-34165MEDIUMUncontrolled search path in some Intel(R) oneAPI DPC++/C++ Compiler before version 2024.2 may allow an authenticated user to potentially enaEPSS 0.2%CVE-2024-21818MEDIUMUncontrolled search path in some Intel(R) PCM software before version 202311 may allow an authenticated user to potentially enable escalatioEPSS 0.2%