Falhas do tipo CWE-427

895 resultados

Caminho de busca ou elemento não controlado

A aplicação procura por um recurso (arquivo, biblioteca, módulo) em múltiplos diretórios sem validar ou controlar a ordem de busca, permitindo que um atacante injete um arquivo malicioso em um caminho que será verificado primeiro. Isso leva a execução de código não autorizado ou bypass de controles de segurança.

Exemplo

Um programa em C carrega uma biblioteca dinâmica (DLL no Windows ou SO no Linux) procurando em diretórios listados em uma variável de ambiente. Se o atacante conseguir escrever um arquivo malicioso com o mesmo nome em um diretório anterior da busca (como o diretório atual), a aplicação carrega a versão maliciosa sem questionar.

Como mitigar

Use caminhos absolutos e hardcoded para recursos críticos; nunca confie em variáveis de ambiente para localizá-los. Valide hash ou assinatura digital de bibliotecas carregadas e restrinja permissões de escrita nos diretórios de busca apenas ao administrador.

CVE-2021-22775A CWE-427: Uncontrolled Search Path Element vulnerability exists in GP-Pro EX,V4.09.250 and prior, that could cause local code execution witEPSS 0.3%CVE-2024-7326HIGHIObit DualSafe Password Manager BPL RTL120.BPL uncontrolled search pathEPSS 0.3%CVE-2022-23449A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versionsEPSS 0.3%CVE-2020-6785HIGHUncontrolled Search Path Element in Bosch BVMS and BVMS ViewerEPSS 0.3%CVE-2021-1536MEDIUMCisco Webex Meetings, Webex Network Recording Player, and Webex Teams DLL Injection VulnerabilityEPSS 0.3%CVE-2022-34235HIGHAdobe Premiere Elements Uncontrolled Search Path Element Privilege EscalationEPSS 0.3%CVE-2025-27237HIGHDLL injection in Zabbix Agent and Agent 2 via OpenSSL configurationEPSS 0.3%CVE-2026-22619HIGHEaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to arbitrary code executEPSS 0.3%CVE-2025-4525HIGHDiscord WINSTA.dll uncontrolled search pathEPSS 0.3%CVE-2021-36631MEDIUMUntrusted search path vulnerability in Baidunetdisk Version 7.4.3 and earlier allows an attacker to gain privileges via a Trojan horse DLL iEPSS 0.3%CVE-2019-3750MEDIUMDell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low prEPSS 0.3%CVE-2019-3749MEDIUMDell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low prEPSS 0.3%CVE-2021-4007HIGHRapid7 Insight Agent Privilege EscalationEPSS 0.3%CVE-2021-1593HIGHCisco Packet Tracer for Windows DLL Injection VulnerabilityEPSS 0.3%CVE-2023-4632HIGHAn uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access to execute codEPSS 0.3%CVE-2022-22528SAP Adaptive Server Enterprise (ASE) - version 16.0, installation makes an entry in the system PATH environment variable in Windows platformEPSS 0.3%CVE-2022-22996HIGHSanDisk Professional G-RAID 4/8 Software Utility, Privilege EscalationEPSS 0.3%CVE-2022-48077HIGHGenymotion Desktop v3.3.2 was discovered to contain a DLL hijacking vulnerability that allows attackers to escalate privileges and execute aEPSS 0.3%CVE-2023-22947HIGHInsecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local atEPSS 0.3%CVE-2025-5129HIGHSangfor 零信任访问控制系统 aTrust MSASN1.dll uncontrolled search pathEPSS 0.3%