Fallos del tipo CWE-427

894 resultados

Busca descontrolada em caminho ou elemento

Ocorre quando uma aplicação procura por um arquivo, biblioteca ou recurso em um caminho sem validação adequada, permitindo que um atacante injete ou substitua o alvo da busca. Um adversário pode colocar um arquivo malicioso em um diretório que será encontrado primeiro, ou manipular a ordem de busca, fazendo o programa executar código não autorizado.

Ejemplo

Um programa busca por uma DLL em C:\Windows\System32 e depois no diretório atual. Se o atacante colocar uma DLL maliciosa no diretório de trabalho, ela será carregada em vez da legítima. Ou um script shell procura por um binário em PATH sem caminho absoluto — um atacante cria uma versão maliciosa em um diretório que vem antes na busca.

Cómo mitigar

Use caminhos absolutos e canonicalizados em vez de busca por caminho; valide cada etapa da resolução antes de usar o recurso; configure permissões restritivas em diretórios de busca e remova diretórios modificáveis do PATH. Em tempo de execução, carregue apenas recursos de locais pré-definidos e confiáveis.

CVE-2020-24440HIGHUncontrolled Search Path Element in Adobe Prelude for WindowsEPSS 0.6%CVE-2024-23940HIGHTrend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and below is vulnerable toEPSS 0.6%CVE-2022-26511WPS Presentation 11.8.0.5745 insecurely load d3dx9_41.dll when opening .pps files('current directory type' DLL loading).EPSS 0.6%CVE-2021-38469CRITICALAUVESY VersiondogEPSS 0.6%CVE-2022-47632MEDIUMRazer Synapse before 3.7.0830.081906 allows privilege escalation due to an unsafe installation path, improper privilege management, and imprEPSS 0.6%CVE-2025-49144HIGHNotepad++ Privilege Escalation in Installer via Uncontrolled Executable Search PathEPSS 0.6%CVE-2017-20018MEDIUMXAMPP Installer uncontrolled search pathEPSS 0.6%CVE-2023-28380HIGHUncontrolled search path for the Intel(R) AI Hackathon software before version 2.0.0 may allow an unauthenticated user to potentially enableEPSS 0.6%CVE-2020-3535HIGHCisco Webex Teams Client for Windows DLL Hijacking VulnerabilityEPSS 0.6%CVE-2025-30248HIGHDLL hijacking in the WD Discovery Installer in Western Digital WD Discovery 5.2.730 on Windows allows a local attacker to execute arbitrary EPSS 0.6%CVE-2017-20051MEDIUMInnoSetup Installer uncontrolled search pathEPSS 0.6%CVE-2023-41790HIGHTraversal Path on PHP fileEPSS 0.6%CVE-2021-30360Users have access to the directory where the installation repair occurs. Since the MS Installer allows regular users to run the repair, an aEPSS 0.6%CVE-2025-26631HIGHVisual Studio Code Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2026-54232HIGHvLLM: Dependency Confusion Vulnerability in vLLM DockerfileEPSS 0.6%CVE-2025-59684HIGHDigiSign DigiSigner ONE 1.0.4.60 allows DLL Hijacking.EPSS 0.6%CVE-2026-65093CRITICALNVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerabiliEPSS 0.5%CVE-2024-5292HIGHD-Link Network Assistant Uncontrolled Search Path Element Local Privilege Escalation VulnerabilityEPSS 0.5%CVE-2017-12313An untrusted search path (aka DLL Preload) vulnerability in the Cisco Network Academy Packet Tracer software could allow an authenticated, lEPSS 0.5%CVE-2023-31210HIGHPrivilege escalation in agent via LD_LIBRARY_PATHEPSS 0.5%