Weaknesses of type CWE-427

897 results

Caminho de busca ou elemento não controlado

A aplicação procura por bibliotecas, configurações ou outros recursos em diretórios sem validar adequadamente quais caminhos ela está usando, permitindo que um atacante injete uma versão maliciosa em um local que será encontrado primeiro. Isso acontece porque a ordem ou composição do caminho de busca não é explicitamente controlada.

Example

Um programa Java com classpath que inclui o diretório atual (.) antes de caminhos do sistema; um atacante coloca uma classe maliciosa no diretório de trabalho e ela é carregada em vez da legítima. Ou um script que procura por um arquivo de configuração em múltiplas pastas sem especificar o caminho absoluto, sendo enganado por um arquivo plantado em /tmp.

How to mitigate

Use caminhos absolutos explícitos em vez de relativos; remova diretórios inseguros (como o atual) do caminho de busca; valide a origem e integridade de recursos carregados (checksums, assinaturas); implemente listas de permitidos para diretórios confiáveis.

CVE-2025-24842MEDIUMUncontrolled search path for the Intel(R) System Support Utility before version 4.1.0 within Ring 3: User Applications may allow an escalatiEPSS 0.1%CVE-2025-7676MEDIUMDLL hijacking of all PE32 executables on Windows 11 for ARM CPUsEPSS 0.1%CVE-2025-20050MEDIUMUncontrolled search path for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escEPSS 0.1%CVE-2026-5397HIGHVulnerability Related to an Uncontrolled Search Path Element in a UPS Management ApplicationEPSS 0.1%CVE-2025-25011HIGHBeats Uncontrolled Search Path Element can lead to Local Privilege Escalation (LPE) when using the Windows InstallerEPSS 0.1%CVE-2024-29015MEDIUMUncontrolled search path in some Intel(R) VTune(TM) Profiler software before versions 2024.1 may allow an authenticated user to potentially EPSS 0.1%CVE-2024-28887MEDIUMUncontrolled search path in some Intel(R) IPP software before version 2021.11 may allow an authenticated user to potentially enable escalatiEPSS 0.1%CVE-2026-24694HIGHThe installer for Roland Cloud Manager ver.3.1.19 and prior insecurely loads Dynamic Link Libraries (DLLs), which could allow an attacker toEPSS 0.1%CVE-2023-52945HIGHUncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local useEPSS 0.1%CVE-2025-26404MEDIUMUncontrolled search path for some Intel(R) DSA software before version 25.2.15.9 may allow an authenticated user to potentially enable escalEPSS 0.1%CVE-2024-34019MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before buiEPSS 0.1%CVE-2024-26027MEDIUMUncontrolled search path for some Intel(R) Simics Package Manager software before version 1.8.3 may allow an authenticated user to potentialEPSS 0.1%CVE-2024-34153MEDIUMUncontrolled search path element in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enablEPSS 0.1%CVE-2025-12852HIGHDLL Loading vulnerability in NEC Corporation RakurakuMusen Start EX All Verisons allows a attacker to manipulate the PC environment to causeEPSS 0.1%CVE-2024-28046MEDIUMUncontrolled search path in some Intel(R) GPA software before version 2024.1 may allow an authenticated user to potentially enable escalatioEPSS 0.1%CVE-2024-49391MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files (Windows) before buiEPSS 0.1%CVE-2025-20092MEDIUMUncontrolled search path for some Clock Jitter Tool software before version 6.0.1 may allow an authenticated user to potentially enable escaEPSS 0.1%CVE-2024-34017MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before buiEPSS 0.1%CVE-2025-40979HIGHDLL search order hijack in Wave by Grandstream NetworksEPSS 0.1%CVE-2024-24977MEDIUMUncontrolled search path for some Intel(R) License Manager for FLEXlm product software before version 11.19.5.0 may allow an authenticated uEPSS 0.1%