Fallos del tipo CWE-427

896 resultados

Busca descontrolada em caminho ou elemento

Ocorre quando uma aplicação procura por um arquivo, biblioteca ou recurso em um caminho sem validação adequada, permitindo que um atacante injete ou substitua o alvo da busca. Um adversário pode colocar um arquivo malicioso em um diretório que será encontrado primeiro, ou manipular a ordem de busca, fazendo o programa executar código não autorizado.

Ejemplo

Um programa busca por uma DLL em C:\Windows\System32 e depois no diretório atual. Se o atacante colocar uma DLL maliciosa no diretório de trabalho, ela será carregada em vez da legítima. Ou um script shell procura por um binário em PATH sem caminho absoluto — um atacante cria uma versão maliciosa em um diretório que vem antes na busca.

Cómo mitigar

Use caminhos absolutos e canonicalizados em vez de busca por caminho; valide cada etapa da resolução antes de usar o recurso; configure permissões restritivas em diretórios de busca e remova diretórios modificáveis do PATH. Em tempo de execução, carregue apenas recursos de locais pré-definidos e confiáveis.

CVE-2025-20041MEDIUMUncontrolled search path for some Intel(R) Graphics software for Intel(R) Arc™ graphics and Intel(R) Iris(R) Xe graphics before version 32.0EPSS 0.2%CVE-2026-28700MEDIUMUncontrolled search path for some EquiTriton before version f5ddbb5 within Ring 3: User Applications may allow an escalation of privilege. UEPSS 0.2%CVE-2025-52541HIGHA DLL hijacking vulnerability in Vivado could allow a local attacker to achieve privilege escalation, potentially resulting in arbitrary codEPSS 0.2%CVE-2026-21408MEDIUMbeat-access for Windows version 3.0.3 and prior contains an issue with the DLL search path, which may lead to insecurely loading Dynamic LinEPSS 0.2%CVE-2025-20079MEDIUMUncontrolled search path for some Intel(R) Advisor software may allow an authenticated user to potentially enable escalation of privilege viEPSS 0.2%CVE-2024-22376MEDIUMUncontrolled search path element in some installation software for Intel(R) Ethernet Adapter Driver Pack before version 28.3 may allow an auEPSS 0.2%CVE-2022-50808HIGHCoolerMaster MasterPlus 1.8.5 - 'MPService' Unquoted Service PathEPSS 0.2%CVE-2023-51710MEDIUMEMS SQL Manager 3.6.2 (build 55333) for Oracle allows DLL hijacking: a user can trigger the execution of arbitrary code every time the produEPSS 0.2%CVE-2023-2355MEDIUMLocal privilege escalation due to a DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before bEPSS 0.2%CVE-2024-47196MEDIUMA vulnerability has been identified in ModelSim (All versions < V2025.2), Questa (All versions < V2025.2). vsimk.exe in affected applicationEPSS 0.2%CVE-2024-47194MEDIUMA vulnerability has been identified in ModelSim (All versions < V2024.3), Questa (All versions < V2024.3). vish2.exe in affected applicationEPSS 0.2%CVE-2026-25264HIGHUncontrolled Search Path Element in Qualcomm Software CenterEPSS 0.2%CVE-2026-47937HIGHAcrobat Reader | Uncontrolled Search Path Element (CWE-427)EPSS 0.2%CVE-2025-62185MEDIUMIn Ankitects Anki before 25.02.5, a crafted shared deck can place a YouTube downloader executable in the media folder, and this is executed EPSS 0.2%CVE-2024-47195MEDIUMA vulnerability has been identified in ModelSim (All versions < V2024.3), Questa (All versions < V2024.3). gdb.exe in affected applications EPSS 0.2%CVE-2024-21784MEDIUMUncontrolled search path for some Intel(R) IPP Cryptography software before version 2021.11 may allow an authenticated user to potentially eEPSS 0.1%CVE-2026-6421HIGHMobatek MobaXterm Home Edition msimg32.dll uncontrolled search pathEPSS 0.1%CVE-2025-62776HIGHThe installer of WTW EAGLE (for Windows) 3.0.8.0 contains an issue with the DLL search path, which may lead to insecurely loading Dynamic LiEPSS 0.1%CVE-2024-23907MEDIUMUncontrolled search path in some Intel(R) High Level Synthesis Compiler software before version 23.4 may allow an authenticated user to poteEPSS 0.1%CVE-2025-64695HIGHUncontrolled search path element issue exists in the installer of LogStare Collector (for Windows). If exploited, arbitrary code may be execEPSS 0.1%