Fallos del tipo CWE-427

897 resultados

Busca descontrolada em caminho ou elemento

Ocorre quando uma aplicação procura por um arquivo, biblioteca ou recurso em um caminho sem validação adequada, permitindo que um atacante injete ou substitua o alvo da busca. Um adversário pode colocar um arquivo malicioso em um diretório que será encontrado primeiro, ou manipular a ordem de busca, fazendo o programa executar código não autorizado.

Ejemplo

Um programa busca por uma DLL em C:\Windows\System32 e depois no diretório atual. Se o atacante colocar uma DLL maliciosa no diretório de trabalho, ela será carregada em vez da legítima. Ou um script shell procura por um binário em PATH sem caminho absoluto — um atacante cria uma versão maliciosa em um diretório que vem antes na busca.

Cómo mitigar

Use caminhos absolutos e canonicalizados em vez de busca por caminho; valide cada etapa da resolução antes de usar o recurso; configure permissões restritivas em diretórios de busca e remova diretórios modificáveis do PATH. Em tempo de execução, carregue apenas recursos de locais pré-definidos e confiáveis.

CVE-2026-56090HIGHDell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerability. A low privileged attacker with loEPSS 0.1%CVE-2026-1636MEDIUMA potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticaEPSS 0.1%CVE-2025-54519HIGHA DLL hijacking vulnerability in Doc Nav could allow a local attacker to achieve privilege escalation, potentially resulting in arbitrary coEPSS 0.1%CVE-2026-4545HIGHFlos Freeware Notepad2 PROPSYS.dll uncontrolled search pathEPSS 0.1%CVE-2026-10847HIGHLocal Privilege Escalation vulnerability in Check Point Identity Agent Full for Windows OSEPSS 0.1%CVE-2026-44612HIGHBytello Share (Windows Edition) installer executable provided by Bytello insecurely loads Dynamic Link Libraries. If there is a crafted DLL EPSS 0.1%CVE-2025-9059HIGHElevation of Privileges Vulnerability in IT Management SuiteEPSS 0.1%CVE-2026-82649HIGHSiYuan before 3.8.1 Local Privilege Escalation via Uncontrolled Search PathEPSS 0.1%CVE-2025-7472HIGHA local privilege escalation vulnerability in the Intercept X for Windows installer prior version 1.22 can lead to a local user gaining systEPSS 0.1%CVE-2024-6510HIGHLocal privilege escalation vulnerability in AVG Internet SecurityEPSS 0.1%CVE-2025-15569HIGHArtifex MuPDF win_main.c get_system_dpi uncontrolled search pathEPSS 0.1%CVE-2024-36333HIGHA DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potentially resulting in arEPSS 0.1%CVE-2026-2516HIGHUnidocs ezPDF DRM Reader/ezPDF Reader SHFOLDER.dll uncontrolled search pathEPSS 0.1%CVE-2024-47091MEDIUMPrivilege escalation via mk_mysql agent plugin on WindowsEPSS 0.1%CVE-2025-20065MEDIUMUncontrolled search path for some Display Virtualization for Windows OS software before version 1797 within Ring 2: Device Drivers may allowEPSS 0.1%CVE-2025-13670MEDIUMHigh Level Synthesis Compiler Security AdvisoryEPSS 0.1%CVE-2025-13669MEDIUMHigh Level Synthesis Compiler Security AdvisoryEPSS 0.1%CVE-2025-24491MEDIUMUncontrolled search path for some Intel(R) Killer(TM) Performance Suite software before version killer 4.0 40.25.509.1465 within Ring 3: UseEPSS 0.1%CVE-2025-30182MEDIUMUncontrolled search path for some Intel(R) Distribution for Python software installers before version 2025.2.0 within Ring 3: User ApplicatiEPSS 0.1%CVE-2025-25059MEDIUMUncontrolled search path for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 within Ring 3: User ApplicatEPSS 0.1%