Fallos del tipo CWE-427

896 resultados

Busca descontrolada em caminho ou elemento

Ocorre quando uma aplicação procura por um arquivo, biblioteca ou recurso em um caminho sem validação adequada, permitindo que um atacante injete ou substitua o alvo da busca. Um adversário pode colocar um arquivo malicioso em um diretório que será encontrado primeiro, ou manipular a ordem de busca, fazendo o programa executar código não autorizado.

Ejemplo

Um programa busca por uma DLL em C:\Windows\System32 e depois no diretório atual. Se o atacante colocar uma DLL maliciosa no diretório de trabalho, ela será carregada em vez da legítima. Ou um script shell procura por um binário em PATH sem caminho absoluto — um atacante cria uma versão maliciosa em um diretório que vem antes na busca.

Cómo mitigar

Use caminhos absolutos e canonicalizados em vez de busca por caminho; valide cada etapa da resolução antes de usar o recurso; configure permissões restritivas em diretórios de busca e remova diretórios modificáveis do PATH. Em tempo de execução, carregue apenas recursos de locais pré-definidos e confiáveis.

CVE-2026-41567HIGHDocker: `PUT /containers/{id}/archive` executes container binary on the hostEPSS 0.2%CVE-2026-28704HIGHEmocheck insecurely loads Dynamic Link Libraries (DLLs). If a crafted DLL file is placed to the same directory, an arbitrary code may be exeEPSS 0.2%CVE-2026-30896HIGHThe installer for Qsee Client versions 1.0.1 and prior insecurely load Dynamic Link Libraries (DLLs). When a user is directed to place some EPSS 0.2%CVE-2026-32679HIGHThe installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the installers of CanonEPSS 0.2%CVE-2026-15515HIGHTencent PC Manager QMUDisk Driver qmudisk64.sys uncontrolled search pathEPSS 0.2%CVE-2024-38383MEDIUMUncontrolled search path for some Intel(R) Quartus(R) Prime Pro Edition software for Windows before version 24.2 may allow an authenticated EPSS 0.2%CVE-2024-36253MEDIUMUncontrolled search path in the Intel(R) SDP Tool for Windows software all version may allow an authenticated user to potentially enable escEPSS 0.2%CVE-2024-38668MEDIUMUncontrolled search path for some Intel(R) Quartus(R) Prime Standard Edition software for Windows before version 23.1.1 may allow an authentEPSS 0.2%CVE-2025-2272HIGHPrivilege Escalation and Arbitrary code execution in F1E EndpointEPSS 0.2%CVE-2023-25944MEDIUMUncontrolled search path element in some Intel(R) VCUST Tool software downloaded before February 3nd 2023 may allow an authenticated user toEPSS 0.2%CVE-2022-43456MEDIUMUncontrolled search path in some Intel(R) RST software before versions 16.8.5.1014.5, 17.11.3.1010.2, 18.7.6.1011.2 and 19.5.2.1049.5 may alEPSS 0.2%CVE-2023-28405MEDIUMUncontrolled search path in the Intel(R) Distribution of OpenVINO(TM) Toolkit before version 2022.3.0 may allow an authenticated user to potEPSS 0.2%CVE-2022-25864MEDIUMUncontrolled search path in some Intel(R) oneMKL software before version 2022.0 may allow an authenticated user to potentially enable escalaEPSS 0.2%CVE-2023-31197MEDIUMUncontrolled search path in the Intel(R) Trace Analyzer and Collector before version 2020 update 3 may allow an authenticated user to potentEPSS 0.2%CVE-2023-29151MEDIUMUncontrolled search path element in some Intel(R) PSR SDK before version 1.0.0.20 may allow an authenticated user to potentially enable escaEPSS 0.2%CVE-2026-83598HIGHNetdata: Local Privilege Escalation in Netdata Agent Windows installer via PowerShell Profile Hijack in MSI RepairEPSS 0.2%CVE-2024-39820MEDIUMZoom Workplace Desktop App for macOS - Uncontrolled Search Path ElementEPSS 0.2%CVE-2026-24016HIGHThe installer of ServerView Agents for Windows provided by Fsas Technologies Inc. may insecurely load Dynamic Link Libraries. Arbitrary codeEPSS 0.2%CVE-2025-20108MEDIUMUncontrolled search path element for some Intel(R) Network Adapter Driver installers for Windows 11 before version 29.4 may allow an authentEPSS 0.2%CVE-2025-7427MEDIUMUncontrolled Search Path Element in Arm Development Studio before 2025EPSS 0.2%