Weaknesses of type CWE-427

897 results

Caminho de busca ou elemento não controlado

A aplicação procura por bibliotecas, configurações ou outros recursos em diretórios sem validar adequadamente quais caminhos ela está usando, permitindo que um atacante injete uma versão maliciosa em um local que será encontrado primeiro. Isso acontece porque a ordem ou composição do caminho de busca não é explicitamente controlada.

Example

Um programa Java com classpath que inclui o diretório atual (.) antes de caminhos do sistema; um atacante coloca uma classe maliciosa no diretório de trabalho e ela é carregada em vez da legítima. Ou um script que procura por um arquivo de configuração em múltiplas pastas sem especificar o caminho absoluto, sendo enganado por um arquivo plantado em /tmp.

How to mitigate

Use caminhos absolutos explícitos em vez de relativos; remova diretórios inseguros (como o atual) do caminho de busca; valide a origem e integridade de recursos carregados (checksums, assinaturas); implemente listas de permitidos para diretórios confiáveis.

CVE-2025-20017MEDIUMUncontrolled search path for some Intel(R) oneAPI Toolkit and component software installers may allow an authenticated user to potentially eEPSS 0.1%CVE-2025-22838MEDIUMUncontrolled search path for some Intel(R) RealSense(TM) Dynamic Calibrator software before version 2.14.2.0 may allow an authenticated userEPSS 0.1%CVE-2025-54519HIGHA DLL hijacking vulnerability in Doc Nav could allow a local attacker to achieve privilege escalation, potentially resulting in arbitrary coEPSS 0.1%CVE-2026-28711MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 17 (Windows) beforEPSS 0.1%CVE-2026-25852MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before EPSS 0.1%CVE-2026-1636MEDIUMA potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticaEPSS 0.1%CVE-2026-28712MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 17 (Windows) beforEPSS 0.1%CVE-2026-28728MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before builEPSS 0.1%CVE-2026-27774MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before builEPSS 0.1%CVE-2026-10847HIGHLocal Privilege Escalation vulnerability in Check Point Identity Agent Full for Windows OSEPSS 0.1%CVE-2025-9059HIGHElevation of Privileges Vulnerability in IT Management SuiteEPSS 0.1%CVE-2026-32323HIGHMullvad VPN for macOS: Local Privilege Escalation via unverified bundle path in installerEPSS 0.1%CVE-2024-6510HIGHLocal privilege escalation vulnerability in AVG Internet SecurityEPSS 0.1%CVE-2025-15569HIGHArtifex MuPDF win_main.c get_system_dpi uncontrolled search pathEPSS 0.1%CVE-2025-7472HIGHA local privilege escalation vulnerability in the Intercept X for Windows installer prior version 1.22 can lead to a local user gaining systEPSS 0.1%CVE-2026-6935HIGHMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.1%CVE-2024-36333HIGHA DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potentially resulting in arEPSS 0.1%CVE-2026-2516HIGHUnidocs ezPDF DRM Reader/ezPDF Reader SHFOLDER.dll uncontrolled search pathEPSS 0.1%CVE-2024-47091MEDIUMPrivilege escalation via mk_mysql agent plugin on WindowsEPSS 0.1%CVE-2025-24491MEDIUMUncontrolled search path for some Intel(R) Killer(TM) Performance Suite software before version killer 4.0 40.25.509.1465 within Ring 3: UseEPSS 0.1%