Falhas do tipo CWE-427

896 resultados

Caminho de busca ou elemento não controlado

A aplicação procura por um recurso (arquivo, biblioteca, módulo) em múltiplos diretórios sem validar ou controlar a ordem de busca, permitindo que um atacante injete um arquivo malicioso em um caminho que será verificado primeiro. Isso leva a execução de código não autorizado ou bypass de controles de segurança.

Exemplo

Um programa em C carrega uma biblioteca dinâmica (DLL no Windows ou SO no Linux) procurando em diretórios listados em uma variável de ambiente. Se o atacante conseguir escrever um arquivo malicioso com o mesmo nome em um diretório anterior da busca (como o diretório atual), a aplicação carrega a versão maliciosa sem questionar.

Como mitigar

Use caminhos absolutos e hardcoded para recursos críticos; nunca confie em variáveis de ambiente para localizá-los. Valide hash ou assinatura digital de bibliotecas carregadas e restrinja permissões de escrita nos diretórios de busca apenas ao administrador.

CVE-2022-22736HIGHIf Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched the current directoryEPSS 0.2%CVE-2023-39929MEDIUMUncontrolled search path in some Libva software maintained by Intel(R) before version 2.20.0 may allow an authenticated user to potentially EPSS 0.2%CVE-2022-30696Local privilege escalation due to a DLL hijacking vulnerabilityEPSS 0.2%CVE-2022-22139HIGHUncontrolled search path in the Intel(R) XTU software before version 7.3.0.33 may allow an authenticated user to potentially enable escalatiEPSS 0.2%CVE-2025-32780HIGHBleachBit for Windows Has DLL Untrusted Path VulnerabilityEPSS 0.2%CVE-2026-49241HIGHAngular: Multiple Remote Code Execution Vulnerabilities in Angular Language Service VS Code ExtensionEPSS 0.2%CVE-2024-8299HIGHMalicious Code Execution Vulnerability in GENESIS64, ICONICS Suite, Hyper Historian, MC Works64, and GENESIS32EPSS 0.2%CVE-2024-9852HIGHMalicious Code Execution Vulnerability in GENESIS64, ICONICS Suite, Hyper Historian, MC Works64, and GENESIS32EPSS 0.2%CVE-2024-9499HIGHUncontrolled search path can lead to DLL hijacking in USBXpress Win 98SE Dev Kit installerEPSS 0.2%CVE-2024-9046HIGHA DLL hijack vulnerability was reported in Lenovo stARstudio that could allow a local attacker to execute code with elevated privileges.EPSS 0.2%CVE-2021-33101HIGHUncontrolled search path in the Intel(R) GPA software before version 21.2 may allow an authenticated user to potentially enable escalation oEPSS 0.2%CVE-2024-9496HIGHUncontrolled search path can lead to DLL hijacking in USBXpress Dev Kit installerEPSS 0.2%CVE-2024-9497HIGHUncontrolled search path can lead to DLL hijacking in USBXpress 4 SDK installerEPSS 0.2%CVE-2021-0169MEDIUMUncontrolled Search Path Element in software for Intel(R) PROSet/Wireless Wi-Fi in Windows 10 and 11 may allow a privileged user to potentiaEPSS 0.2%CVE-2025-43553HIGHSubstance3D - Modeler | Uncontrolled Search Path Element (CWE-427)EPSS 0.2%CVE-2022-0025MEDIUMCortex XDR Agent: An Uncontrolled Search Path Element Leads to Local Privilege Escalation (PE) VulnerabilityEPSS 0.2%CVE-2022-24426HIGHDell Command | Update, Dell Update, and Alienware Update version 4.4.0 contains a Local Privilege Escalation Vulnerability in the Advanced DEPSS 0.2%CVE-2025-23358HIGHNVIDIA NVApp for Windows contains a vulnerability in the installer, where a local attacker can cause a search path element issue. A successfEPSS 0.2%CVE-2021-44206Local privilege escalation due to DLL hijacking vulnerability in Acronis Media Builder serviceEPSS 0.2%CVE-2023-34350MEDIUMUncontrolled search path element in some Intel(R) XTU software before version 7.12.0.15 may allow an authenticated user to potentially enablEPSS 0.2%