Fallos del tipo CWE-427

896 resultados

Busca descontrolada em caminho ou elemento

Ocorre quando uma aplicação procura por um arquivo, biblioteca ou recurso em um caminho sem validação adequada, permitindo que um atacante injete ou substitua o alvo da busca. Um adversário pode colocar um arquivo malicioso em um diretório que será encontrado primeiro, ou manipular a ordem de busca, fazendo o programa executar código não autorizado.

Ejemplo

Um programa busca por uma DLL em C:\Windows\System32 e depois no diretório atual. Se o atacante colocar uma DLL maliciosa no diretório de trabalho, ela será carregada em vez da legítima. Ou um script shell procura por um binário em PATH sem caminho absoluto — um atacante cria uma versão maliciosa em um diretório que vem antes na busca.

Cómo mitigar

Use caminhos absolutos e canonicalizados em vez de busca por caminho; valide cada etapa da resolução antes de usar o recurso; configure permissões restritivas em diretórios de busca e remova diretórios modificáveis do PATH. Em tempo de execução, carregue apenas recursos de locais pré-definidos e confiáveis.

CVE-2024-47576LOWDLL Hijacking vulnerability in SAP Product Lifecycle CostingEPSS 0.2%CVE-2024-42405MEDIUMUncontrolled search path for some Intel(R) Quartus(R) Prime Software before version 23.1.1 Patch 1.01std may allow an authenticated user to EPSS 0.2%CVE-2026-54672HIGHelectron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`EPSS 0.2%CVE-2024-12530HIGHInsecure Dynamic-Link Library (DLL) Load vulnerabilityEPSS 0.2%CVE-2024-47006MEDIUMUncontrolled search path for the Intel(R) RealSense D400 Series Universal Windows Platform (UWP) Driver for Windows(R) 10 all versions may aEPSS 0.2%CVE-2022-34396HIGH Dell OpenManage Server Administrator (OMSA) version 10.3.0.0 and earlier contains a DLL Injection Vulnerability. A local low privileged autEPSS 0.2%CVE-2022-32498MEDIUMDell EMC PowerStore, Versions prior to v3.0.0.0 contain a DLL Hijacking vulnerability in PSTCLI. A local attacker can potentially exploit thEPSS 0.2%CVE-2024-22346HIGHIBM i privilege escalationEPSS 0.2%CVE-2024-42492MEDIUMUncontrolled search path element in some BIOS and System Firmware Update Package for Intel(R) Server M50FCP family before version R01.02.000EPSS 0.2%CVE-2024-48091HIGHTally Prime Edit Log v2.1 was discovered to contain a DLL hijacking vulnerability via the component TextShaping.dll. This vulnerability alloEPSS 0.2%CVE-2025-30167HIGHJupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2024-22167HIGHSanDisk PrivateAccess DLL Hijacking VulnerabilityEPSS 0.2%CVE-2025-4769HIGHCBEWIN Anytxt Searcher ATService.exe uncontrolled search pathEPSS 0.2%CVE-2026-21427HIGHThe installers for multiple products provided by PIONEER CORPORATION contain an issue with the DLL search path, which may lead to insecurelyEPSS 0.2%CVE-2024-13976HIGHCommvault 11.20.0 - 11.36.0 Windows Maintenance Installer DLL InjectionEPSS 0.2%CVE-2025-64994MEDIUMPrivilege Escalation via Uncontrolled Search Path in 1E-Nomad-SetWorkRate instructionEPSS 0.2%CVE-2024-21837MEDIUMUncontrolled search path in some Intel(R) Quartus(R) Prime Lite Edition Design software before version 23.1 may allow an authenticated user EPSS 0.2%CVE-2024-21862MEDIUMUncontrolled search path in some Intel(R) Quartus(R) Prime Standard Edition Design software before version 23.1 may allow an authenticated uEPSS 0.2%CVE-2024-21814MEDIUMUncontrolled search path for some Intel(R) Chipset Device Software before version 10.1.19444.8378 may allow an authenticated user to potentiEPSS 0.2%CVE-2025-26624MEDIUMLocal Privilege Escalation in Rufus 4.6 and previous versionsEPSS 0.2%