Falhas do tipo CWE-426

322 resultados

Caminho de busca não confiável

A aplicação procura por arquivos ou bibliotecas em diretórios cuja ordem ou conteúdo pode ser controlado por um atacante. Ao carregar uma DLL, biblioteca dinâmica ou executável sem validar o caminho completo, o programa pode ser enganado a usar um arquivo malicioso plantado em um local que é percorrido antes do legítimo.

Exemplo

Um programa Windows que carrega 'msvcrt.dll' sem especificar o caminho completo. Se o atacante coloca uma DLL maliciosa com o mesmo nome no diretório de trabalho ou em um PATH que a aplicação vasculha primeiro, a versão maliciosa é carregada em vez da legítima — permitindo execução de código arbitrário.

Como mitigar

Sempre especifique o caminho absoluto completo ao carregar bibliotecas dinâmicas ou executáveis; use mecanismos da plataforma (como LoadLibraryEx no Windows com LOAD_LIBRARY_SEARCH_SYSTEM32) que restringem o escopo de busca; valide a integridade e assinatura dos arquivos antes de carregar; remova diretórios inseguros da variável PATH da aplicação.

CVE-2019-6196MEDIUMA symbolic link vulnerability in some Lenovo installation packages, prior to version 1.2.9.3, could allow privileged file operations during EPSS 0.3%CVE-2020-8096MEDIUMUntrusted Search Path Vulnerability in High-Level Antimalware SDKEPSS 0.3%CVE-2024-24697HIGHZoom Clients - Untrusted Search PathEPSS 0.3%CVE-2024-6975HIGHCato Networks Windows SDP Client Local Privilege Escalation via openssl configuration fileEPSS 0.3%CVE-2025-4455HIGHPatch My PC Home Updater System.IO uncontrolled search pathEPSS 0.3%CVE-2026-48346HIGHAnimate | Untrusted Search Path (CWE-426)EPSS 0.3%CVE-2026-39883HIGHOpenTelemetry-Go has an incomplete fix for CVE-2026-24051: BSD kenv command not using absolute path enables PATH hijackingEPSS 0.3%CVE-2025-24789HIGHSnowflake JDBC allows an untrusted search path on WindowsEPSS 0.3%CVE-2026-25926HIGHNotepad++ has an Untrusted Search PathEPSS 0.3%CVE-2025-15321LOWTanium addressed an improper input validation vulnerability in Tanium Appliance.EPSS 0.3%CVE-2025-9267HIGHIn Seagate Toolkit on Windows a vulnerability exists in the Toolkit Installer prior to versions 2.35.0.6 where it attempts to load DLLs fromEPSS 0.3%CVE-2026-21280HIGHIllustrator | Untrusted Search Path (CWE-426)EPSS 0.3%CVE-2022-0014MEDIUMCortex XDR Agent: Unintended Program Execution When Using Live Terminal SessionEPSS 0.3%CVE-2024-49515HIGHSubstance3D - Painter | Untrusted Search Path (CWE-426)EPSS 0.3%CVE-2026-40287HIGHPraisonAI has RCE via Automatic tools.py ImportEPSS 0.2%CVE-2024-44103HIGHDLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker EPSS 0.2%CVE-2024-6974HIGHCato Networks Windows SDP Client Local Privilege Escalation via self-upgradeEPSS 0.2%CVE-2021-31841HIGHDLL side loading vulnerability in MA for WindowsEPSS 0.2%CVE-2024-24810HIGHWiX is vulnerable to DLL redirection attacks that allow the attacker to escalate privilegesEPSS 0.2%CVE-2023-48670HIGH Dell SupportAssist for Home PCs version 3.14.1 and prior versions contain a privilege escalation vulnerability in the installer. A local loEPSS 0.2%