Falhas do tipo CWE-426

322 resultados

Caminho de busca não confiável

A aplicação procura por arquivos ou bibliotecas em diretórios cuja ordem ou conteúdo pode ser controlado por um atacante. Ao carregar uma DLL, biblioteca dinâmica ou executável sem validar o caminho completo, o programa pode ser enganado a usar um arquivo malicioso plantado em um local que é percorrido antes do legítimo.

Exemplo

Um programa Windows que carrega 'msvcrt.dll' sem especificar o caminho completo. Se o atacante coloca uma DLL maliciosa com o mesmo nome no diretório de trabalho ou em um PATH que a aplicação vasculha primeiro, a versão maliciosa é carregada em vez da legítima — permitindo execução de código arbitrário.

Como mitigar

Sempre especifique o caminho absoluto completo ao carregar bibliotecas dinâmicas ou executáveis; use mecanismos da plataforma (como LoadLibraryEx no Windows com LOAD_LIBRARY_SEARCH_SYSTEM32) que restringem o escopo de busca; valide a integridade e assinatura dos arquivos antes de carregar; remova diretórios inseguros da variável PATH da aplicação.

CVE-2023-27771HIGHAn issue found in Wondershare Technology Co.,Ltd Creative Centerr v.1.0.8 allows a remote attacker to execute arbitrary commands via the wonEPSS 0.4%CVE-2023-27763HIGHAn issue found in Wondershare Technology Co.,Ltd MobileTrans v.4.0.2 allows a remote attacker to execute arbitrary commands via the mobiletrEPSS 0.4%CVE-2023-27760HIGHAn issue found in Wondershare Technology Co, Ltd Filmora v.12.0.9 allows a remote attacker to execute arbitrary commands via the filmora_setEPSS 0.4%CVE-2023-27761HIGHAn issue found in Wondershare Technology Co., Ltd UniConverter v.14.0.0 allows a remote attacker to execute arbitrary commands via the unicoEPSS 0.4%CVE-2023-27768HIGHAn issue found in Wondershare Technology Co.,Ltd PDFelement v9.1.1 allows a remote attacker to execute arbitrary commands via the pdfelementEPSS 0.4%CVE-2023-27769HIGHAn issue found in Wondershare Technology Co.,Ltd PDF Reader v.1.0.1 allows a remote attacker to execute arbitrary commands via the pdfreaderEPSS 0.4%CVE-2026-48565HIGHWindows Narrator Braille Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2020-7279MEDIUMDLL search order hijacking in Host IPSEPSS 0.4%CVE-2026-23888MEDIUMpnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)EPSS 0.4%CVE-2020-7476A CWE-426: Untrusted Search Path vulnerability exists in ZigBee Installation Kit (Versions prior to 1.0.1), which could cause execution of mEPSS 0.4%CVE-2024-55503LOWAn issue in termius before v.9.9.0 allows a local attacker to execute arbitrary code via a crafted script to the DYLD_INSERT_LIBRARIES compoEPSS 0.4%CVE-2020-8317HIGHA DLL search path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated uEPSS 0.4%CVE-2026-16674HIGHIBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server LibertyEPSS 0.4%CVE-2020-6654HIGHDLL HijackingEPSS 0.4%CVE-2025-60718HIGHWindows Administrator Protection Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2019-25257HIGHLogicalDOC Enterprise 7.7.4 Authenticated Command Execution via Binary Path ManipulationEPSS 0.4%CVE-2021-25698The OpenSSL component of the Teradici PCoIP Standard Agent prior to version 21.07.0 was compiled without the no-autoload-config option, whicEPSS 0.4%CVE-2021-25699The OpenSSL component of the Teradici PCoIP Software Client prior to version 21.07.0 was compiled without the no-autoload-config option, whiEPSS 0.4%CVE-2022-31012HIGHGit for Windows' installer can be tricked into executing an untrusted binaryEPSS 0.4%CVE-2021-28246HIGHCA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. A regulaEPSS 0.4%