Fallos del tipo CWE-427

896 resultados

Busca descontrolada em caminho ou elemento

Ocorre quando uma aplicação procura por um arquivo, biblioteca ou recurso em um caminho sem validação adequada, permitindo que um atacante injete ou substitua o alvo da busca. Um adversário pode colocar um arquivo malicioso em um diretório que será encontrado primeiro, ou manipular a ordem de busca, fazendo o programa executar código não autorizado.

Ejemplo

Um programa busca por uma DLL em C:\Windows\System32 e depois no diretório atual. Se o atacante colocar uma DLL maliciosa no diretório de trabalho, ela será carregada em vez da legítima. Ou um script shell procura por um binário em PATH sem caminho absoluto — um atacante cria uma versão maliciosa em um diretório que vem antes na busca.

Cómo mitigar

Use caminhos absolutos e canonicalizados em vez de busca por caminho; valide cada etapa da resolução antes de usar o recurso; configure permissões restritivas em diretórios de busca e remova diretórios modificáveis do PATH. Em tempo de execução, carregue apenas recursos de locais pré-definidos e confiáveis.

CVE-2022-25841HIGHUncontrolled search path elements in the Intel(R) Datacenter Group Event Android application, all versions, may allow an authenticated user EPSS 0.2%CVE-2025-49571HIGHSubstance3D - Modeler | Uncontrolled Search Path Element (CWE-427)EPSS 0.2%CVE-2023-32646MEDIUMUncontrolled search path element in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enaEPSS 0.2%CVE-2026-5055HIGHNoMachine Uncontrolled Search Path Element Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2022-27180MEDIUMUncontrolled search path in the Intel(R) MacCPUID software before version 3.2 may allow an authenticated user to potentially enable escalatiEPSS 0.2%CVE-2024-7061MEDIUMOkta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows vEPSS 0.2%CVE-2025-1131HIGHAsterisk Unsafe Shell Sourcing in safe_asterisk Leads to Local Privilege EscalationEPSS 0.2%CVE-2022-32972HIGHInfoblox BloxOne Endpoint for Windows through 2.2.7 allows DLL injection that can result in local privilege escalation.EPSS 0.2%CVE-2023-0213HIGHLocal Elevation of Privilege in M-FilesEPSS 0.2%CVE-2023-3662HIGHCODESYS: Vulnerability in CODESYS Development System allows for execution of binariesEPSS 0.2%CVE-2023-31016HIGHCVEEPSS 0.2%CVE-2026-76199HIGHPhotoshop Desktop | Uncontrolled Search Path Element (CWE-427)EPSS 0.2%CVE-2026-4546HIGHFlos Freeware Notepad2 TextShaping.dll uncontrolled search pathEPSS 0.2%CVE-2025-4539HIGHHainan ToDesk DLL File Parser profapi.dll uncontrolled search pathEPSS 0.2%CVE-2022-41796HIGHUntrusted search path vulnerability in the installer of Content Transfer (for Windows) Ver.1.3 and prior allows an attacker to gain privilegEPSS 0.2%CVE-2021-3423HIGHPrivilege escalation in Bitdefender GravityZone Business SecurityEPSS 0.2%CVE-2024-10093HIGHVSO ConvertXtoDvd ConvertXtoDvd.exe uncontrolled search pathEPSS 0.2%CVE-2026-42171HIGHNSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing locEPSS 0.2%CVE-2026-0487HIGHDLL Hijacking vulnerability in SAProuter on Microsoft WindowsEPSS 0.2%CVE-2023-6338HIGHUncontrolled search path vulnerabilities were reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local aEPSS 0.2%