Fallos del tipo CWE-427

896 resultados

Busca descontrolada em caminho ou elemento

Ocorre quando uma aplicação procura por um arquivo, biblioteca ou recurso em um caminho sem validação adequada, permitindo que um atacante injete ou substitua o alvo da busca. Um adversário pode colocar um arquivo malicioso em um diretório que será encontrado primeiro, ou manipular a ordem de busca, fazendo o programa executar código não autorizado.

Ejemplo

Um programa busca por uma DLL em C:\Windows\System32 e depois no diretório atual. Se o atacante colocar uma DLL maliciosa no diretório de trabalho, ela será carregada em vez da legítima. Ou um script shell procura por um binário em PATH sem caminho absoluto — um atacante cria uma versão maliciosa em um diretório que vem antes na busca.

Cómo mitigar

Use caminhos absolutos e canonicalizados em vez de busca por caminho; valide cada etapa da resolução antes de usar o recurso; configure permissões restritivas em diretórios de busca e remova diretórios modificáveis do PATH. Em tempo de execução, carregue apenas recursos de locais pré-definidos e confiáveis.

CVE-2022-31611MEDIUM NVIDIA GeForce Experience contains an uncontrolled search path vulnerability in all its client installers, where an attacker with user leveEPSS 0.2%CVE-2023-33874MEDIUMUncontrolled search path in some Intel(R) NUC 12 Pro Kits & Mini PCs - NUC12WS Intel(R) HID Event Filter Driver installation software beforeEPSS 0.2%CVE-2023-22355MEDIUMUncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticatEPSS 0.2%CVE-2023-45743MEDIUMUncontrolled search path in some Intel(R) DSA software uninstallers before version 23.4.39.10 may allow an authenticated user to potentiallyEPSS 0.2%CVE-2025-30033HIGHThe affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user iEPSS 0.2%CVE-2026-18718HIGHGhidra Swift Demangler Analyzer Arbitrary Code Execution via Project StateEPSS 0.2%CVE-2026-5674HIGHPipewire: pipewire: sandbox escape and arbitrary code execution via malicious library loadingEPSS 0.2%CVE-2023-39374HIGH ForeScout NAC SecureConnector – CWE-427: Uncontrolled Search Path ElementEPSS 0.2%CVE-2024-29223MEDIUMUncontrolled search path for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentialEPSS 0.2%CVE-2023-34430MEDIUMUncontrolled search path in some Intel Battery Life Diagnostic Tool software before version 2.2.1 may allow an authenticated user to potentiEPSS 0.2%CVE-2022-45422HIGHWhen LG SmartShare is installed, local privilege escalation is possible through DLL Hijacking attack. The LG ID is LVE-HOT-220005.EPSS 0.2%CVE-2023-41961MEDIUMUncontrolled search path in some Intel(R) GPA software before version 2023.3 may allow an authenticated user to potentially enable escalatioEPSS 0.2%CVE-2023-35192MEDIUMUncontrolled search path in some Intel(R) GPA Framework software before version 2023.3 may allow an authenticated user to potentially enableEPSS 0.2%CVE-2024-37127HIGHDell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially eEPSS 0.2%CVE-2024-49592MEDIUMTrial installer for McAfee Total Protection (legacy trial installer software) 16.0.53 allows local privilege escalation because of an UncontEPSS 0.2%CVE-2024-20430HIGHCisco Meraki Systems Manager Agent for Windows Privilege Escalation VulnerabilityEPSS 0.2%CVE-2024-30117LOWHCL BigFix Platform is affected by a DLL Hijack vulnerabilityEPSS 0.2%CVE-2024-22450HIGHDell Alienware Command Center, versions prior to 6.2.7.0, contain an uncontrolled search path element vulnerability. A local malicious user EPSS 0.2%CVE-2024-39372MEDIUMUncontrolled search path for the Intel(R) XTU software for Windows before version 7.14.2.14 may allow an authenticated user to potentially eEPSS 0.2%CVE-2024-39365MEDIUMUncontrolled search path for the FPGA Support Package for the Intel(R) oneAPI DPC++/C++ Compiler software for Windows before version 2024.2 EPSS 0.2%