Fallos del tipo CWE-426

322 resultados

Busca em caminho não confiável

Ocorre quando uma aplicação procura por bibliotecas, executáveis ou arquivos em diretórios cuja ordem ou conteúdo não é totalmente controlado, permitindo que um atacante injete uma versão maliciosa de um arquivo antes da legítima ser encontrada. O risco é a execução de código não autorizado com os privilégios da aplicação.

Ejemplo

Uma aplicação precisa carregar a biblioteca 'libssl.so'. Se o PATH inclui o diretório /tmp antes de /usr/lib, um atacante coloca uma libssl.so maliciosa em /tmp — a aplicação carregará a falsa sem saber. Comum em scripts e instaladores que não usam caminhos absolutos.

Cómo mitigar

Use caminhos absolutos e completos ao fazer busca de arquivos críticos (não confie em PATH ou variáveis de ambiente). Valide integridade e propriedade de arquivos encontrados; configure o PATH explicitamente apenas com diretórios confiáveis; em sistemas Unix, remova '.' e /tmp da ordem de busca.

CVE-2023-27759HIGHAn issue found in Wondershare Technology Co, Ltd Edrawmind v.10.0.6 allows a remote attacker to executea arbitrary commands via the WindowsCEPSS 0.4%CVE-2026-45772NONETurborepo: Unexpected local code execution during Yarn Berry detectionEPSS 0.4%CVE-2023-23618HIGHgitk can inadvertently call executables in the worktreeEPSS 0.4%CVE-2024-28133HIGHPHOENIX CONTACT: Privilege escalation in CHARX Series EPSS 0.4%CVE-2023-29299MEDIUMAdobe Acrobat Reader Untrusted Search Path Application denial-of-serviceEPSS 0.4%CVE-2025-12819HIGHUntrusted search path in auth_query connection in PgBouncerEPSS 0.4%CVE-2022-36070HIGHPoetry's Untrusted Search Path can lead to Local Code Execution on WindowsEPSS 0.4%CVE-2025-49124HIGHApache Tomcat: exe side-loading via icalcs.exe in Tomcat installer for WindowsEPSS 0.4%CVE-2023-1521HIGHLocal Privilege Escalation in sccacheEPSS 0.4%CVE-2023-26358HIGHAdobe Creative Cloud AdobeExtensionService.exe local privilege escalation vulnerabilityEPSS 0.4%CVE-2023-22743HIGHGit for Windows' installer is susceptible to DLL side loading attacksEPSS 0.4%CVE-2024-47422HIGHAdobe Framemaker | Untrusted Search Path (CWE-426)EPSS 0.4%CVE-2019-17100MEDIUMUntrusted Search Path vulnerability in Bitdefender Total Security 2020 (VA-5895)EPSS 0.3%CVE-2020-6023Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to escalate privileges while restoring files in Anti-Ransomware.EPSS 0.3%CVE-2024-41865HIGHAdobe Dimension Untrusted Search Path lead to load malicious DLL swift.dllEPSS 0.3%CVE-2024-20754HIGHLightroom Desktop | Untrusted Search Path (CWE-426)EPSS 0.3%CVE-2022-31253HIGHopenldap2: /usr/lib/openldap/start allows ldap user/group to recursively chown arbitrary directory trees to itselfEPSS 0.3%CVE-2021-3305HIGHBeijing Feishu Technology Co., Ltd Feishu v3.40.3 was discovered to contain an untrusted search path vulnerability.EPSS 0.3%CVE-2024-9325HIGHIntelbras InControl incontrol-service-watchdog.exe unquoted search pathEPSS 0.3%CVE-2024-38305HIGHDell SupportAssist for Home PCs Installer exe version 4.0.3 contains a privilege escalation vulnerability in the installer. A local low-privEPSS 0.3%