Falhas do tipo CWE-427

895 resultados

Caminho de busca ou elemento não controlado

A aplicação procura por um recurso (arquivo, biblioteca, módulo) em múltiplos diretórios sem validar ou controlar a ordem de busca, permitindo que um atacante injete um arquivo malicioso em um caminho que será verificado primeiro. Isso leva a execução de código não autorizado ou bypass de controles de segurança.

Exemplo

Um programa em C carrega uma biblioteca dinâmica (DLL no Windows ou SO no Linux) procurando em diretórios listados em uma variável de ambiente. Se o atacante conseguir escrever um arquivo malicioso com o mesmo nome em um diretório anterior da busca (como o diretório atual), a aplicação carrega a versão maliciosa sem questionar.

Como mitigar

Use caminhos absolutos e hardcoded para recursos críticos; nunca confie em variáveis de ambiente para localizá-los. Valide hash ou assinatura digital de bibliotecas carregadas e restrinja permissões de escrita nos diretórios de busca apenas ao administrador.

CVE-2020-6021Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repaEPSS 0.3%CVE-2023-6891MEDIUMPeaZip Library dragdropfilesdll.dll uncontrolled search pathEPSS 0.3%CVE-2025-32917MEDIUMPrivilege escalation in jar_signatureEPSS 0.3%CVE-2022-48422HIGHONLYOFFICE Docs through 7.3 on certain Linux distributions allows local users to gain privileges via a Trojan horse libgcc_s.so.1 in the curEPSS 0.3%CVE-2024-7834HIGHLocal privilege escalation in OverwolfEPSS 0.3%CVE-2024-39613MEDIUMRCE in desktop app in Windows by local attackerEPSS 0.3%CVE-2024-34116HIGHAdobe Creative Cloud App Install Arbitrary Folder Delete Vulnerability can be abuse to Privilege EscalationEPSS 0.3%CVE-2026-25129MEDIUMPsySH has Local Privilege Escalation via CWD .psysh.php auto-loadEPSS 0.3%CVE-2025-5480HIGHAction1 Uncontrolled Search Path Element Local Privilege Escalation VulnerabilityEPSS 0.3%CVE-2022-28714HIGHOn F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prEPSS 0.3%CVE-2020-5316HIGHDell SupportAssist for Business PCs versions 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3 and Dell SupportAssist for Home PCs version 2.0, 2.EPSS 0.3%CVE-2023-44220SonicWall NetExtender Windows (32-bit and 64-bit) client 10.2.336 and earlier versions have a DLL Search Order Hijacking vulnerability in thEPSS 0.3%CVE-2019-3745MEDIUMThe vulnerability is limited to the installers of Dell Encryption Enterprise versions prior to 10.4.0 and Dell Endpoint Security Suite EnterEPSS 0.3%CVE-2025-5180HIGHWondershare Filmora Installer NFWCHK.exe uncontrolled search pathEPSS 0.3%CVE-2025-23177HIGHRibbon Communications - CWE-427: Uncontrolled Search Path ElementEPSS 0.3%CVE-2026-2361HIGHImproper search_path protection in PostgreSQL Anonymizer 2.5 allows any user with create privilege to gain superuser privilegesEPSS 0.3%CVE-2020-7358MEDIUMCode Injection in Rapid7 AppSpider Pro InstallerEPSS 0.3%CVE-2024-7244HIGHPanda Security Dome VPN DLL Hijacking Local Privilege Escalation VulnerabilityEPSS 0.3%CVE-2025-21127HIGHPhotoshop Desktop | Uncontrolled Search Path Element (CWE-427)EPSS 0.3%CVE-2021-21545HIGHDell Peripheral Manager 1.3.1 or greater contains remediation for a local privilege escalation vulnerability that could be potentially exploEPSS 0.3%