Fallos del tipo CWE-427

896 resultados

Busca descontrolada em caminho ou elemento

Ocorre quando uma aplicação procura por um arquivo, biblioteca ou recurso em um caminho sem validação adequada, permitindo que um atacante injete ou substitua o alvo da busca. Um adversário pode colocar um arquivo malicioso em um diretório que será encontrado primeiro, ou manipular a ordem de busca, fazendo o programa executar código não autorizado.

Ejemplo

Um programa busca por uma DLL em C:\Windows\System32 e depois no diretório atual. Se o atacante colocar uma DLL maliciosa no diretório de trabalho, ela será carregada em vez da legítima. Ou um script shell procura por um binário em PATH sem caminho absoluto — um atacante cria uma versão maliciosa em um diretório que vem antes na busca.

Cómo mitigar

Use caminhos absolutos e canonicalizados em vez de busca por caminho; valide cada etapa da resolução antes de usar o recurso; configure permissões restritivas em diretórios de busca e remova diretórios modificáveis do PATH. Em tempo de execução, carregue apenas recursos de locais pré-definidos e confiáveis.

CVE-2024-21831MEDIUMUncontrolled search path in some Intel(R) Processor Diagnostic Tool software before version 4.1.9.41 may allow an authenticated user to poteEPSS 0.2%CVE-2024-47942HIGHA vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 9). The affected applications suffer from a DLL hijacEPSS 0.2%CVE-2024-53588HIGHA DLL hijacking vulnerability in iTop VPN v16.0 allows attackers to execute arbitrary code via placing a crafted DLL file into the path \ProEPSS 0.2%CVE-2025-64772HIGHThe installer of INZONE Hub 1.0.10.3 to 1.0.17.0 contains an issue with the DLL search path, which may lead to insecurely loading Dynamic LiEPSS 0.2%CVE-2024-9493HIGHUncontrolled search path can lead to DLL hijacking in ToolStick installerEPSS 0.2%CVE-2024-9492HIGHUncontrolled search path can lead to DLL hijacking in Flash Programming Utility installerEPSS 0.2%CVE-2024-9491HIGHUncontrolled search path can lead to DLL hijacking in Configuration Wizard 2 installerEPSS 0.2%CVE-2020-8895HIGHDLL Hijacking in Google Earth Pro Windows installerEPSS 0.2%CVE-2024-9490HIGHUncontrolled search path can lead to DLL hijacking in Silicon Labs IDE installerEPSS 0.2%CVE-2024-28099HIGHVT STUDIO Ver.8.32 and earlier contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As aEPSS 0.2%CVE-2024-9495HIGHUncontrolled search path can lead to DLL hijacking in CP210x VCP Windows installerEPSS 0.2%CVE-2025-31931MEDIUMUncontrolled search path for the Instrumentation and Tracing Technology API (ITT API) software before version 3.25.4 within Ring 3: User AppEPSS 0.2%CVE-2024-28131HIGHEasyRange Ver 1.41 contains an issue with the executable file search path when displaying an extracted file on Explorer, which may lead to lEPSS 0.2%CVE-2024-29734HIGHUncontrolled search path element issue exists in SonicDICOM Media Viewer 2.3.2 and earlier, which may lead to insecurely loading Dynamic LinEPSS 0.2%CVE-2022-34755MEDIUM A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged account to place a sEPSS 0.2%CVE-2024-9494HIGHUncontrolled search path can lead to DLL hijacking in CP210 VCP Win 2k installerEPSS 0.2%CVE-2024-21774MEDIUMUncontrolled search path in some Intel(R) Processor Identification Utility software before versions 6.10.34.1129, 7.1.6 may allow an authentEPSS 0.2%CVE-2024-33578HIGHA DLL hijack vulnerability was reported in Lenovo Leyun that could allow a local attacker to execute code with elevated privileges.EPSS 0.2%CVE-2024-12530HIGHInsecure Dynamic-Link Library (DLL) Load vulnerabilityEPSS 0.2%CVE-2024-22167HIGHSanDisk PrivateAccess DLL Hijacking VulnerabilityEPSS 0.2%