Falhas do tipo CWE-427

895 resultados

Caminho de busca ou elemento não controlado

A aplicação procura por um recurso (arquivo, biblioteca, módulo) em múltiplos diretórios sem validar ou controlar a ordem de busca, permitindo que um atacante injete um arquivo malicioso em um caminho que será verificado primeiro. Isso leva a execução de código não autorizado ou bypass de controles de segurança.

Exemplo

Um programa em C carrega uma biblioteca dinâmica (DLL no Windows ou SO no Linux) procurando em diretórios listados em uma variável de ambiente. Se o atacante conseguir escrever um arquivo malicioso com o mesmo nome em um diretório anterior da busca (como o diretório atual), a aplicação carrega a versão maliciosa sem questionar.

Como mitigar

Use caminhos absolutos e hardcoded para recursos críticos; nunca confie em variáveis de ambiente para localizá-los. Valide hash ou assinatura digital de bibliotecas carregadas e restrinja permissões de escrita nos diretórios de busca apenas ao administrador.

CVE-2023-24578MEDIUMMcAfee Total Protection prior to 16.0.49 allows attackers to elevate user privileges due to DLL sideloading. This could enable a user with lEPSS 0.3%CVE-2025-9267HIGHIn Seagate Toolkit on Windows a vulnerability exists in the Toolkit Installer prior to versions 2.35.0.6 where it attempts to load DLLs fromEPSS 0.3%CVE-2022-36924HIGHLocal Privilege Escalation in Zoom Rooms Installer for WindowsEPSS 0.3%CVE-2020-5324HIGHDell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is limited to the Dell FiEPSS 0.3%CVE-2026-3775HIGHFoxit PDF Editor/Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation VulnerabilityEPSS 0.3%CVE-2023-4931MEDIUMUncontrolled search path element vulnerability in PleskEPSS 0.2%CVE-2022-28792MEDIUMDLL hijacking vulnerability in Gear IconX PC Manager prior to version 2.1.220405.51 allows attacker to execute arbitrary code. The patch addEPSS 0.2%CVE-2023-31361HIGHA DLL hijacking vulnerability in AMD Integrated Management Technology (AIM-T) Manageability Service could allow an attacker to achieve priviEPSS 0.2%CVE-2023-48677HIGHLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Home Office (WindoEPSS 0.2%CVE-2020-25244HIGHA vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). The software insecurely loads libraries which makes it vulnEPSS 0.2%CVE-2021-3042HIGHCortex XDR Agent: Improper Control of User-Controlled File Leads to Local Privilege EscalationEPSS 0.2%CVE-2021-3041HIGHCortex XDR Agent: Improper control of user-controlled file leads to local privilege escalationEPSS 0.2%CVE-2023-47113HIGHDLL Search Order Hijacking vulnerability in BleachBit for WindowsEPSS 0.2%CVE-2026-25655HIGHA vulnerability has been identified in SINEC NMS (All versions < V4.0 SP2). The affected application permits improper modification of a confEPSS 0.2%CVE-2026-25656HIGHA vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3), User Management Component (UMC) (All versions < V2.15.2.1). The EPSS 0.2%CVE-2022-0192HIGHA DLL search path vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow privilege escalation.EPSS 0.2%CVE-2021-3550HIGHA DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.500.5102, that could allow privilege escalation.EPSS 0.2%CVE-2023-22818HIGHMultiple DLL Search Order hijacking Vulnerabilities in SanDisk Security Installer for Windows EPSS 0.2%CVE-2022-1098HIGHDelta Electronics DIAEnergie Uncontrolledly Search Path ElementEPSS 0.2%CVE-2022-22736HIGHIf Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched the current directoryEPSS 0.2%