Falhas do tipo CWE-426

322 resultados

Caminho de busca não confiável

A aplicação procura por arquivos ou bibliotecas em diretórios cuja ordem ou conteúdo pode ser controlado por um atacante. Ao carregar uma DLL, biblioteca dinâmica ou executável sem validar o caminho completo, o programa pode ser enganado a usar um arquivo malicioso plantado em um local que é percorrido antes do legítimo.

Exemplo

Um programa Windows que carrega 'msvcrt.dll' sem especificar o caminho completo. Se o atacante coloca uma DLL maliciosa com o mesmo nome no diretório de trabalho ou em um PATH que a aplicação vasculha primeiro, a versão maliciosa é carregada em vez da legítima — permitindo execução de código arbitrário.

Como mitigar

Sempre especifique o caminho absoluto completo ao carregar bibliotecas dinâmicas ou executáveis; use mecanismos da plataforma (como LoadLibraryEx no Windows com LOAD_LIBRARY_SEARCH_SYSTEM32) que restringem o escopo de busca; valide a integridade e assinatura dos arquivos antes de carregar; remova diretórios inseguros da variável PATH da aplicação.

CVE-2026-48391HIGHBridge | Untrusted Search Path (CWE-426)EPSS 0.2%CVE-2024-6080HIGHIntelbras InControl incontrolWebcam Service unquoted search pathEPSS 0.2%CVE-2023-22368HIGHUntrusted search path vulnerability in ELECOM Camera Assistant 1.00 and QuickFileDealer Ver.1.2.1 and earlier allows an attacker to gain priEPSS 0.2%CVE-2026-0299MEDIUMGlobalProtect App: Local Privilege Escalation VulnerabilitiesEPSS 0.2%CVE-2024-13524LOWobsproject OBS Studio untrusted search pathEPSS 0.2%CVE-2024-7995HIGHAutodesk VRED Design Privilege Escalation VulnerabilityEPSS 0.2%CVE-2023-36536HIGH Untrusted search path in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalaEPSS 0.2%CVE-2025-0567LOWEpic Games Launcher Installer profapi.dll untrusted search pathEPSS 0.2%CVE-2025-4532HIGHShanghai Bairui Information Technology SunloginClient sunlogin_guard.exe uncontrolled search pathEPSS 0.2%CVE-2026-25880HIGHUntrusted Search Path in SumatraPDF Reader (explorer.exe on Windows)EPSS 0.2%CVE-2024-11454HIGHUntrusted Search Path vulnerability in Autodesk RevitEPSS 0.2%CVE-2023-36538HIGHImproper access control in Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilegeEPSS 0.2%CVE-2025-0707HIGHRise Group Rise Mode Temp CPU Startup CRYPTBASE.dll untrusted search pathEPSS 0.2%CVE-2024-7886HIGHScooter Software Beyond Compare 7zxa.dll uncontrolled search pathEPSS 0.2%CVE-2026-25792MEDIUMGreenshot Vulnerable to OS Command Injection via ExternalCommand PluginEPSS 0.2%CVE-2025-4272HIGHMechrevo Control Console GCUService csCAPI.dll uncontrolled search pathEPSS 0.2%CVE-2022-35868MEDIUMA vulnerability has been identified in TIA Multiuser Server V14 (All versions), TIA Multiuser Server V15 (All versions < V15.1 Update 8), TIEPSS 0.2%CVE-2025-0459MEDIUMlibretro RetroArch Startup profapi.dll untrusted search pathEPSS 0.2%CVE-2023-34119HIGHInsecure temporary file in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalEPSS 0.2%CVE-2020-8094HIGHUntrusted Search Path Vulnerability in Bitdefender Antivirus Free 2020 (VA-8422)EPSS 0.2%