Falhas do tipo CWE-426

322 resultados

Caminho de busca não confiável

A aplicação procura por arquivos ou bibliotecas em diretórios cuja ordem ou conteúdo pode ser controlado por um atacante. Ao carregar uma DLL, biblioteca dinâmica ou executável sem validar o caminho completo, o programa pode ser enganado a usar um arquivo malicioso plantado em um local que é percorrido antes do legítimo.

Exemplo

Um programa Windows que carrega 'msvcrt.dll' sem especificar o caminho completo. Se o atacante coloca uma DLL maliciosa com o mesmo nome no diretório de trabalho ou em um PATH que a aplicação vasculha primeiro, a versão maliciosa é carregada em vez da legítima — permitindo execução de código arbitrário.

Como mitigar

Sempre especifique o caminho absoluto completo ao carregar bibliotecas dinâmicas ou executáveis; use mecanismos da plataforma (como LoadLibraryEx no Windows com LOAD_LIBRARY_SEARCH_SYSTEM32) que restringem o escopo de busca; valide a integridade e assinatura dos arquivos antes de carregar; remova diretórios inseguros da variável PATH da aplicação.

CVE-2025-24830MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (WindoEPSS 0.1%CVE-2025-24827MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (WindoEPSS 0.1%CVE-2025-24828MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (WindoEPSS 0.1%CVE-2026-35368HIGHuutils coreutils chroot Local Privilege Escalation and chroot Escape in via Name Service Switch (NSS) InjectionEPSS 0.1%CVE-2026-29089HIGHTimescaleDB uses untrusted search path during extension upgradeEPSS 0.1%CVE-2025-12793HIGHAn uncontrolled DLL loading path vulnerability exists in AsusSoftwareManagerAgent. A local attacker may influence the application to load a EPSS 0.1%CVE-2026-53842HIGHOpenClaw < 2026.5.2 - Arbitrary Python Runtime Execution via CLOUDSDK_PYTHON Environment VariableEPSS 0.1%CVE-2026-32009HIGHOpenClaw < 2026.2.24 - Binary Hijacking via Static Default Trusted Directories in safeBinsEPSS 0.1%CVE-2025-30407MEDIUMLocal privilege escalation due to a binary hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (EPSS 0.1%CVE-2026-40947LOWYubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before 5.9.1 have an unintended DLL search path.EPSS 0.1%CVE-2026-82862HIGHHulumi before v1.3.2 Helper Script Shadowing via Workspace FilesEPSS 0.1%CVE-2026-32015HIGHOpenClaw 2026.1.21 < 2026.2.19 - PATH Hijacking Bypass in tools.exec.safeBins Allowlist ValidationEPSS 0.1%CVE-2025-67722MEDIUMAuthenticated amportal search for ‘freepbx_engine’ in non root writeable directories leads to potential privilege escalationEPSS 0.1%CVE-2026-32032HIGHOpenClaw < 2026.2.22 - Arbitrary Shell Execution via Unvalidated SHELL Environment VariableEPSS 0.1%CVE-2026-4545HIGHFlos Freeware Notepad2 PROPSYS.dll uncontrolled search pathEPSS 0.1%CVE-2024-14012HIGHPotential Privilege Escalation in Revenera InstallShield 2023 R1EPSS 0.1%CVE-2026-53858HIGHOpenClaw < 2026.5.2 - Arbitrary Runtime Dependency Loading via STATE_DIRECTORY Environment VariableEPSS 0.1%CVE-2026-16869HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%CVE-2026-53865HIGHOpenClaw < 2026.5.2 - Arbitrary Command Execution via Workspace-Derived Service PATHEPSS 0.1%CVE-2026-32016HIGHOpenClaw < 2026.2.22 - Path Traversal via Basename-Only Allowlist Matching on macOSEPSS 0.1%