Fallos del tipo CWE-427

896 resultados

Busca descontrolada em caminho ou elemento

Ocorre quando uma aplicação procura por um arquivo, biblioteca ou recurso em um caminho sem validação adequada, permitindo que um atacante injete ou substitua o alvo da busca. Um adversário pode colocar um arquivo malicioso em um diretório que será encontrado primeiro, ou manipular a ordem de busca, fazendo o programa executar código não autorizado.

Ejemplo

Um programa busca por uma DLL em C:\Windows\System32 e depois no diretório atual. Se o atacante colocar uma DLL maliciosa no diretório de trabalho, ela será carregada em vez da legítima. Ou um script shell procura por um binário em PATH sem caminho absoluto — um atacante cria uma versão maliciosa em um diretório que vem antes na busca.

Cómo mitigar

Use caminhos absolutos e canonicalizados em vez de busca por caminho; valide cada etapa da resolução antes de usar o recurso; configure permissões restritivas em diretórios de busca e remova diretórios modificáveis do PATH. Em tempo de execução, carregue apenas recursos de locais pré-definidos e confiáveis.

CVE-2026-9169HIGHLUCID Vision Labs: DLL Search Order Hijacking in Arena SDK 1.0.80.49 on WindowsEPSS 0.1%CVE-2026-34488HIGHIP Setting Software contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arEPSS 0.1%CVE-2024-28953MEDIUMUncontrolled search path in some EMON software before version 11.44 may allow an authenticated user to potentially enable escalation of privEPSS 0.1%CVE-2024-8766MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (WindoEPSS 0.1%CVE-2026-40031HIGHMemProcFS < 5.17 DLL/Shared Library HijackingEPSS 0.1%CVE-2026-92180HIGHpdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation VulnerabilityEPSS 0.1%CVE-2025-20050MEDIUMUncontrolled search path for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escEPSS 0.1%CVE-2026-47274MEDIUMpam_usb: Uncontrolled search path in pam_usb tools allows privilege escalation via PATH manipulationEPSS 0.1%CVE-2025-24842MEDIUMUncontrolled search path for the Intel(R) System Support Utility before version 4.1.0 within Ring 3: User Applications may allow an escalatiEPSS 0.1%CVE-2025-7676MEDIUMDLL hijacking of all PE32 executables on Windows 11 for ARM CPUsEPSS 0.1%CVE-2025-25011HIGHBeats Uncontrolled Search Path Element can lead to Local Privilege Escalation (LPE) when using the Windows InstallerEPSS 0.1%CVE-2026-6958HIGHAcunetix 25.11.251107123 Local Privilege Escalation via wvsc.exeEPSS 0.1%CVE-2024-29015MEDIUMUncontrolled search path in some Intel(R) VTune(TM) Profiler software before versions 2024.1 may allow an authenticated user to potentially EPSS 0.1%CVE-2024-28887MEDIUMUncontrolled search path in some Intel(R) IPP software before version 2021.11 may allow an authenticated user to potentially enable escalatiEPSS 0.1%CVE-2026-24694HIGHThe installer for Roland Cloud Manager ver.3.1.19 and prior insecurely loads Dynamic Link Libraries (DLLs), which could allow an attacker toEPSS 0.1%CVE-2024-34019MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before buiEPSS 0.1%CVE-2025-20092MEDIUMUncontrolled search path for some Clock Jitter Tool software before version 6.0.1 may allow an authenticated user to potentially enable escaEPSS 0.1%CVE-2025-40979HIGHDLL search order hijack in Wave by Grandstream NetworksEPSS 0.1%CVE-2025-26404MEDIUMUncontrolled search path for some Intel(R) DSA software before version 25.2.15.9 may allow an authenticated user to potentially enable escalEPSS 0.1%CVE-2026-92838HIGHGeoVision GV-Remote E-Map dll hijacking vulnerabilityEPSS 0.1%