Weaknesses of type CWE-427

897 results

Caminho de busca ou elemento não controlado

A aplicação procura por bibliotecas, configurações ou outros recursos em diretórios sem validar adequadamente quais caminhos ela está usando, permitindo que um atacante injete uma versão maliciosa em um local que será encontrado primeiro. Isso acontece porque a ordem ou composição do caminho de busca não é explicitamente controlada.

Example

Um programa Java com classpath que inclui o diretório atual (.) antes de caminhos do sistema; um atacante coloca uma classe maliciosa no diretório de trabalho e ela é carregada em vez da legítima. Ou um script que procura por um arquivo de configuração em múltiplas pastas sem especificar o caminho absoluto, sendo enganado por um arquivo plantado em /tmp.

How to mitigate

Use caminhos absolutos explícitos em vez de relativos; remova diretórios inseguros (como o atual) do caminho de busca; valide a origem e integridade de recursos carregados (checksums, assinaturas); implemente listas de permitidos para diretórios confiáveis.

CVE-2025-20065MEDIUMUncontrolled search path for some Display Virtualization for Windows OS software before version 1797 within Ring 2: Device Drivers may allowEPSS 0.1%CVE-2025-13669MEDIUMHigh Level Synthesis Compiler Security AdvisoryEPSS 0.1%CVE-2025-25059MEDIUMUncontrolled search path for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 within Ring 3: User ApplicatEPSS 0.1%CVE-2025-30182MEDIUMUncontrolled search path for some Intel(R) Distribution for Python software installers before version 2025.2.0 within Ring 3: User ApplicatiEPSS 0.1%CVE-2025-24491MEDIUMUncontrolled search path for some Intel(R) Killer(TM) Performance Suite software before version killer 4.0 40.25.509.1465 within Ring 3: UseEPSS 0.1%CVE-2025-13670MEDIUMHigh Level Synthesis Compiler Security AdvisoryEPSS 0.1%CVE-2025-13162MEDIUMAdvant Master Online Builder DLL vulnerabilityEPSS 0.1%CVE-2026-59781MEDIUMImproper validation of custom installation directories on Windows could allow installation into locations with unsafe permissions, increasing the risk of DLL sideloading.EPSS 0.1%CVE-2026-91803HIGHSecurity Vulnerability Report – Foxit PDF Editor/Reader Updater DLL Search Path HijackingEPSS 0.1%CVE-2025-11792HIGHLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (WindoEPSS 0.1%CVE-2026-0294MEDIUMPrisma Access Agent: Local Privilege EscalationEPSS 0.1%CVE-2025-13665MEDIUMQuartus Prime Standard Security AdvisoryEPSS 0.1%CVE-2025-31647MEDIUMUncontrolled search path for some Intel(R) Graphics Software before version 25.22.1502.2 within Ring 3: User Applications may allow an escalEPSS 0.1%CVE-2025-13668MEDIUMQuartus Prime Pro Edition AdvisoryEPSS 0.1%CVE-2025-35972MEDIUMUncontrolled search path for the Intel MPI Library before version 2021.16 within Ring 3: User Applications may allow an escalation of privilEPSS 0.1%CVE-2025-31645MEDIUMUncontrolled search path for some System Event Log Viewer Utility software for all versions within Ring 3: User Applications may allow an esEPSS 0.1%CVE-2025-13664MEDIUMQuartus Prime Standard Security AdvisoryEPSS 0.1%CVE-2025-32038MEDIUMUncontrolled search path for some FPGA Support Package for the Intel oneAPI DPC++C++ Compiler software before version 2025.0.1 within Ring 3EPSS 0.1%CVE-2025-32001MEDIUMUncontrolled search path for the Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User Applications may allow EPSS 0.1%CVE-2025-62628HIGHUnsafe OpenSSL initialization within some AMD optional tools may allow a local user-privileged attacker to inject a malicious DLL, potentialEPSS 0.1%