Falhas do tipo CWE-427

895 resultados

Caminho de busca ou elemento não controlado

A aplicação procura por um recurso (arquivo, biblioteca, módulo) em múltiplos diretórios sem validar ou controlar a ordem de busca, permitindo que um atacante injete um arquivo malicioso em um caminho que será verificado primeiro. Isso leva a execução de código não autorizado ou bypass de controles de segurança.

Exemplo

Um programa em C carrega uma biblioteca dinâmica (DLL no Windows ou SO no Linux) procurando em diretórios listados em uma variável de ambiente. Se o atacante conseguir escrever um arquivo malicioso com o mesmo nome em um diretório anterior da busca (como o diretório atual), a aplicação carrega a versão maliciosa sem questionar.

Como mitigar

Use caminhos absolutos e hardcoded para recursos críticos; nunca confie em variáveis de ambiente para localizá-los. Valide hash ou assinatura digital de bibliotecas carregadas e restrinja permissões de escrita nos diretórios de busca apenas ao administrador.

CVE-2022-28779MEDIUMUncontrolled search path element vulnerability in Samsung Android USB Driver windows installer program prior to version 1.7.50 allows attackEPSS 0.3%CVE-2020-6788HIGHUncontrolled Search Path Element in Bosch Configuration Manager InstallerEPSS 0.3%CVE-2020-6786HIGHUncontrolled Search Path Element in Bosch Video Recording Manager InstallerEPSS 0.3%CVE-2020-6789HIGHUncontrolled Search Path Element in Bosch Monitor Wall InstallerEPSS 0.3%CVE-2020-2049HIGHCortex XDR Agent: Improper control of loaded DLL leads to local privilege escalationEPSS 0.3%CVE-2025-34109HIGHPanda Security PSEvents.exe Insecure DLL Loading Privilege EscalationEPSS 0.3%CVE-2021-3606OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file ifEPSS 0.3%CVE-2022-34902HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacEPSS 0.3%CVE-2022-34901HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacEPSS 0.3%CVE-2026-7870HIGHIBM i is Affected by Privilege Escalation []EPSS 0.3%CVE-2021-21518HIGHDell SupportAssist Client for Consumer PCs versions 3.7.x, 3.6.x, 3.4.x, 3.3.x, Dell SupportAssist Client for Business PCs versions 2.0.x, 2EPSS 0.3%CVE-2019-18575HIGHDell Command Configure versions prior to 4.2.1 contain an uncontrolled search path vulnerability. A locally authenticated malicious user couEPSS 0.3%CVE-2020-6244HIGHSAP Business Client, version 7.0, allows an attacker after a successful social engineering attack to inject malicious code as a DLL file in EPSS 0.3%CVE-2017-5147An Uncontrolled Search Path Element issue was discovered in AzeoTech DAQFactory versions prior to 17.1. An uncontrolled search path element EPSS 0.3%CVE-2026-32172HIGHMicrosoft Power Apps Remote Code Execution VulnerabilityEPSS 0.3%CVE-2018-15452MEDIUMCisco Advanced Malware Protection for Endpoints on Windows DLL Preloading VulnerabilityEPSS 0.3%CVE-2024-0670HIGHPrivilege escalation in windows agentEPSS 0.3%CVE-2023-6401MEDIUMNotePad++ dbghelp.exe uncontrolled search pathEPSS 0.3%CVE-2025-14405MEDIUMPDFsam Enhanced Uncontrolled Search Path Element Local Privilege Escalation VulnerabilityEPSS 0.3%CVE-2021-43940HIGHAffected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the lEPSS 0.3%