Fallos del tipo CWE-427

897 resultados

Busca descontrolada em caminho ou elemento

Ocorre quando uma aplicação procura por um arquivo, biblioteca ou recurso em um caminho sem validação adequada, permitindo que um atacante injete ou substitua o alvo da busca. Um adversário pode colocar um arquivo malicioso em um diretório que será encontrado primeiro, ou manipular a ordem de busca, fazendo o programa executar código não autorizado.

Ejemplo

Um programa busca por uma DLL em C:\Windows\System32 e depois no diretório atual. Se o atacante colocar uma DLL maliciosa no diretório de trabalho, ela será carregada em vez da legítima. Ou um script shell procura por um binário em PATH sem caminho absoluto — um atacante cria uma versão maliciosa em um diretório que vem antes na busca.

Cómo mitigar

Use caminhos absolutos e canonicalizados em vez de busca por caminho; valide cada etapa da resolução antes de usar o recurso; configure permissões restritivas em diretórios de busca e remova diretórios modificáveis do PATH. Em tempo de execução, carregue apenas recursos de locais pré-definidos e confiáveis.

CVE-2025-12852HIGHDLL Loading vulnerability in NEC Corporation RakurakuMusen Start EX All Verisons allows a attacker to manipulate the PC environment to causeEPSS 0.1%CVE-2025-20092MEDIUMUncontrolled search path for some Clock Jitter Tool software before version 6.0.1 may allow an authenticated user to potentially enable escaEPSS 0.1%CVE-2024-28046MEDIUMUncontrolled search path in some Intel(R) GPA software before version 2024.1 may allow an authenticated user to potentially enable escalatioEPSS 0.1%CVE-2024-34017MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before buiEPSS 0.1%CVE-2024-34019MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before buiEPSS 0.1%CVE-2025-27717MEDIUMUncontrolled search path for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enable escalation of privEPSS 0.1%CVE-2024-26027MEDIUMUncontrolled search path for some Intel(R) Simics Package Manager software before version 1.8.3 may allow an authenticated user to potentialEPSS 0.1%CVE-2026-92838HIGHGeoVision GV-Remote E-Map dll hijacking vulnerabilityEPSS 0.1%CVE-2023-52945HIGHUncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local useEPSS 0.1%CVE-2025-0041HIGHUncontrolled search paths in the Vitis™ Embedded Single File Download (SFD) for local Windows installation could allow a low-privileged userEPSS 0.1%CVE-2025-13919MEDIUMComponent Object Model (COM) Hijacking in Symantec Endpoint Protection Windows ClientEPSS 0.1%CVE-2025-40763HIGHA vulnerability has been identified in Altair Grid Engine (All versions < V2026.0.0). Affected products do not properly validate environmentEPSS 0.1%CVE-2026-36574HIGHA DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and execute arbitrary codEPSS 0.1%CVE-2026-40004MEDIUMopenssl.cnf Privilege Escalation Vulnerability in ZTE Cloud PC Client uSmartviewEPSS 0.1%CVE-2025-48503HIGHA DLL hijacking vulnerability in the AMD Software Installer could allow an attacker to achieve privilege escalation potentially resulting inEPSS 0.1%CVE-2024-2207MEDIUMSound Research SECOMN64 Escalation of PrivilegeEPSS 0.1%CVE-2026-22270MEDIUMDell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an uncontrolled search path element vulneEPSS 0.1%CVE-2025-0712HIGHAPM Server Uncontrolled Search Path Element can lead to Local Privilege Escalation (LPE) when using the Windows InstallerEPSS 0.1%CVE-2025-12046HIGHA DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a local authenticated usEPSS 0.1%CVE-2026-87530HIGHUncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to exeEPSS 0.1%