Fallos del tipo CWE-427

895 resultados

Busca descontrolada em caminho ou elemento

Ocorre quando uma aplicação procura por um arquivo, biblioteca ou recurso em um caminho sem validação adequada, permitindo que um atacante injete ou substitua o alvo da busca. Um adversário pode colocar um arquivo malicioso em um diretório que será encontrado primeiro, ou manipular a ordem de busca, fazendo o programa executar código não autorizado.

Ejemplo

Um programa busca por uma DLL em C:\Windows\System32 e depois no diretório atual. Se o atacante colocar uma DLL maliciosa no diretório de trabalho, ela será carregada em vez da legítima. Ou um script shell procura por um binário em PATH sem caminho absoluto — um atacante cria uma versão maliciosa em um diretório que vem antes na busca.

Cómo mitigar

Use caminhos absolutos e canonicalizados em vez de busca por caminho; valide cada etapa da resolução antes de usar o recurso; configure permissões restritivas em diretórios de busca e remova diretórios modificáveis do PATH. Em tempo de execução, carregue apenas recursos de locais pré-definidos e confiáveis.

CVE-2025-30672MEDIUMMite for Perl generates code with an untrusted search path vulnerabilityEPSS 0.4%CVE-2022-34900HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.3 (39313) Agent. An attacEPSS 0.4%CVE-2025-33208HIGHNVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled search path. A successful exploiEPSS 0.4%CVE-2019-25268HIGHNREL BEopt 2.8.0 Insecure Library Loading Arbitrary Code ExecutionEPSS 0.4%CVE-2025-30673MEDIUMSub::HandlesVia for Perl allows untrusted code to be included from the current working directoryEPSS 0.4%CVE-2025-3051MEDIUMLinux::Statm::Tiny for Perl allows untrusted code to be included from the current working directoryEPSS 0.4%CVE-2019-6564—GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to place malicious files within the installer file directorEPSS 0.4%CVE-2021-36216—LINE for Windows 6.2.1.2289 and before allows arbitrary code execution via malicious DLL injection.EPSS 0.4%CVE-2026-54916HIGHNetBox Device Type Library: Module Shadowing Bypass of prior pickle fix - RCE via missing `tests/__init__.py` + SSRF via unfixed `NETBOX_DT_LIBRARY_URL` → Cloud Metadata credential theftEPSS 0.4%CVE-2025-33122HIGHIBM i privilege escalationEPSS 0.4%CVE-2020-6654HIGHDLL HijackingEPSS 0.4%CVE-2024-30376HIGHFamatech Advanced IP Scanner Uncontrolled Search Path Element Local Privilege Escalation VulnerabilityEPSS 0.4%CVE-2017-11158—Multiple untrusted search path vulnerabilities in the installer in Synology Cloud Station Drive before 4.2.5-4396 on Windows allow local attEPSS 0.4%CVE-2026-28456HIGHOpenClaw 2026.1.5 < 2026.2.14 - Arbitrary Code Execution via Unsafe Hook Module Path HandlingEPSS 0.4%CVE-2023-0247HIGHUncontrolled Search Path Element in bits-and-blooms/bloomEPSS 0.4%CVE-2023-26266HIGHIn AFL++ 4.05c, the CmpLog component uses the current working directory to resolve and execute unprefixed fuzzing targets, allowing code exeEPSS 0.4%CVE-2023-30237HIGHCyberGhostVPN Windows Client before v8.3.10.10015 was discovered to contain a DLL injection vulnerability via the component Dashboard.exe.EPSS 0.4%CVE-2025-22458HIGHDLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated attacker to escalate to EPSS 0.4%CVE-2021-1237HIGHCisco AnyConnect Secure Mobility Client for Windows DLL Injection VulnerabilityEPSS 0.4%CVE-2022-46330HIGHSquirrel.Windows is both a toolset and a library that provides installation and update functionality for Windows desktop applications. InstaEPSS 0.4%