Falhas do tipo CWE-426

322 resultados

Caminho de busca não confiável

A aplicação procura por arquivos ou bibliotecas em diretórios cuja ordem ou conteúdo pode ser controlado por um atacante. Ao carregar uma DLL, biblioteca dinâmica ou executável sem validar o caminho completo, o programa pode ser enganado a usar um arquivo malicioso plantado em um local que é percorrido antes do legítimo.

Exemplo

Um programa Windows que carrega 'msvcrt.dll' sem especificar o caminho completo. Se o atacante coloca uma DLL maliciosa com o mesmo nome no diretório de trabalho ou em um PATH que a aplicação vasculha primeiro, a versão maliciosa é carregada em vez da legítima — permitindo execução de código arbitrário.

Como mitigar

Sempre especifique o caminho absoluto completo ao carregar bibliotecas dinâmicas ou executáveis; use mecanismos da plataforma (como LoadLibraryEx no Windows com LOAD_LIBRARY_SEARCH_SYSTEM32) que restringem o escopo de busca; valide a integridade e assinatura dos arquivos antes de carregar; remova diretórios inseguros da variável PATH da aplicação.

CVE-2023-27759HIGHAn issue found in Wondershare Technology Co, Ltd Edrawmind v.10.0.6 allows a remote attacker to executea arbitrary commands via the WindowsCEPSS 0.4%CVE-2026-45772NONETurborepo: Unexpected local code execution during Yarn Berry detectionEPSS 0.4%CVE-2023-23618HIGHgitk can inadvertently call executables in the worktreeEPSS 0.4%CVE-2024-28133HIGHPHOENIX CONTACT: Privilege escalation in CHARX Series EPSS 0.4%CVE-2023-29299MEDIUMAdobe Acrobat Reader Untrusted Search Path Application denial-of-serviceEPSS 0.4%CVE-2025-12819HIGHUntrusted search path in auth_query connection in PgBouncerEPSS 0.4%CVE-2022-36070HIGHPoetry's Untrusted Search Path can lead to Local Code Execution on WindowsEPSS 0.4%CVE-2025-49124HIGHApache Tomcat: exe side-loading via icalcs.exe in Tomcat installer for WindowsEPSS 0.4%CVE-2023-1521HIGHLocal Privilege Escalation in sccacheEPSS 0.4%CVE-2023-26358HIGHAdobe Creative Cloud AdobeExtensionService.exe local privilege escalation vulnerabilityEPSS 0.4%CVE-2024-47422HIGHAdobe Framemaker | Untrusted Search Path (CWE-426)EPSS 0.4%CVE-2023-22743HIGHGit for Windows' installer is susceptible to DLL side loading attacksEPSS 0.4%CVE-2019-17100MEDIUMUntrusted Search Path vulnerability in Bitdefender Total Security 2020 (VA-5895)EPSS 0.3%CVE-2020-6023Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to escalate privileges while restoring files in Anti-Ransomware.EPSS 0.3%CVE-2024-41865HIGHAdobe Dimension Untrusted Search Path lead to load malicious DLL swift.dllEPSS 0.3%CVE-2024-20754HIGHLightroom Desktop | Untrusted Search Path (CWE-426)EPSS 0.3%CVE-2022-31253HIGHopenldap2: /usr/lib/openldap/start allows ldap user/group to recursively chown arbitrary directory trees to itselfEPSS 0.3%CVE-2021-3305HIGHBeijing Feishu Technology Co., Ltd Feishu v3.40.3 was discovered to contain an untrusted search path vulnerability.EPSS 0.3%CVE-2024-9325HIGHIntelbras InControl incontrol-service-watchdog.exe unquoted search pathEPSS 0.3%CVE-2024-38305HIGHDell SupportAssist for Home PCs Installer exe version 4.0.3 contains a privilege escalation vulnerability in the installer. A local low-privEPSS 0.3%