Fallos del tipo CWE-426

322 resultados

Busca em caminho não confiável

Ocorre quando uma aplicação procura por bibliotecas, executáveis ou arquivos em diretórios cuja ordem ou conteúdo não é totalmente controlado, permitindo que um atacante injete uma versão maliciosa de um arquivo antes da legítima ser encontrada. O risco é a execução de código não autorizado com os privilégios da aplicação.

Ejemplo

Uma aplicação precisa carregar a biblioteca 'libssl.so'. Se o PATH inclui o diretório /tmp antes de /usr/lib, um atacante coloca uma libssl.so maliciosa em /tmp — a aplicação carregará a falsa sem saber. Comum em scripts e instaladores que não usam caminhos absolutos.

Cómo mitigar

Use caminhos absolutos e completos ao fazer busca de arquivos críticos (não confie em PATH ou variáveis de ambiente). Valide integridade e propriedade de arquivos encontrados; configure o PATH explicitamente apenas com diretórios confiáveis; em sistemas Unix, remova '.' e /tmp da ordem de busca.

CVE-2024-58250CRITICALThe passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges.EPSS 0.2%CVE-2026-4962HIGHUltraVNC Service version.dll uncontrolled search pathEPSS 0.2%CVE-2021-26738HIGHPrivilege Escalation for ZCC macOS via PATH VariableEPSS 0.2%CVE-2025-27167HIGHIllustrator | Untrusted Search Path (CWE-426)EPSS 0.2%CVE-2026-48395HIGHBridge | Untrusted Search Path (CWE-426)EPSS 0.2%CVE-2026-48287HIGHCAI Content Credentials | Untrusted Search Path (CWE-426)EPSS 0.2%CVE-2021-21562MEDIUMDell EMC PowerScale OneFS contains an untrusted search path vulnerability. This vulnerability allows a user with (ISI_PRIV_LOGIN_SSH or ISI_EPSS 0.2%CVE-2026-33156HIGHDLL Sideloading in ScreenToGifEPSS 0.2%CVE-2026-23512HIGHSumatraPDF has an Untrusted Search Path in sumatrapdf/src/AppTools.cppEPSS 0.2%CVE-2024-47906HIGHExcessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before versiEPSS 0.2%CVE-2024-22410LOWBinary Planting Attack on Windows Platforms in CreditcoinEPSS 0.2%CVE-2026-47648HIGHWindows Storage Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2026-24070HIGHLocal Privilege Escalation via DYLIB Injection in Native Instruments Native AccessEPSS 0.2%CVE-2025-1068HIGHThere is a code injection vulnerability in Esri ArcGIS AllSourceEPSS 0.2%CVE-2026-4546HIGHFlos Freeware Notepad2 TextShaping.dll uncontrolled search pathEPSS 0.2%CVE-2025-0145MEDIUMZoom Workplace Apps for Windows - Untrusted Search PathEPSS 0.2%CVE-2025-4539HIGHHainan ToDesk DLL File Parser profapi.dll uncontrolled search pathEPSS 0.2%CVE-2023-39202LOWUntrusted search path in Zoom Rooms Client for Windows and Zoom VDI Client may allow a privileged user to conduct a denial of service via loEPSS 0.2%CVE-2026-40156HIGHPraisonAI Affected by Implicit Execution of Arbitrary Code via Automatic `tools.py` LoadingEPSS 0.2%CVE-2025-5335HIGHPrivilege Ecalation due to Untrusted Search Path VulnerabilityEPSS 0.2%