Falhas do tipo CWE-427

896 resultados

Caminho de busca ou elemento não controlado

A aplicação procura por um recurso (arquivo, biblioteca, módulo) em múltiplos diretórios sem validar ou controlar a ordem de busca, permitindo que um atacante injete um arquivo malicioso em um caminho que será verificado primeiro. Isso leva a execução de código não autorizado ou bypass de controles de segurança.

Exemplo

Um programa em C carrega uma biblioteca dinâmica (DLL no Windows ou SO no Linux) procurando em diretórios listados em uma variável de ambiente. Se o atacante conseguir escrever um arquivo malicioso com o mesmo nome em um diretório anterior da busca (como o diretório atual), a aplicação carrega a versão maliciosa sem questionar.

Como mitigar

Use caminhos absolutos e hardcoded para recursos críticos; nunca confie em variáveis de ambiente para localizá-los. Valide hash ou assinatura digital de bibliotecas carregadas e restrinja permissões de escrita nos diretórios de busca apenas ao administrador.

CVE-2022-31694HIGHInstallBuilder Qt installers built with versions previous to 22.10 try to load DLLs from the installer binary parent directory when displayiEPSS 0.2%CVE-2022-30697Local privilege escalation due to insecure folder permissionsEPSS 0.2%CVE-2021-42743HIGHLocal privilege escalation via a default path in Splunk Enterprise WindowsEPSS 0.2%CVE-2025-35471HIGHconda-forge openssl-feedstock writable OPENSSLDIREPSS 0.2%CVE-2025-2769HIGHBdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2021-38410HIGHAVEVA PCS Portal Uncontrolled Search Path ElementEPSS 0.2%CVE-2025-2768HIGHBdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2023-25005HIGHA maliciously crafted DLL file can be forced to read beyond allocated boundaries in Autodesk InfraWorks 2023, and 2021 when parsing the DLL EPSS 0.2%CVE-2023-28140MEDIUMExecutable HijackingEPSS 0.2%CVE-2022-23401The following Yokogawa Electric products contain insecure DLL loading issues. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP vEPSS 0.2%CVE-2023-3078HIGHAn uncontrolled search path vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local aEPSS 0.2%CVE-2021-41544HIGHA vulnerability has been identified in Siemens Software Center (All versions < V3.0). A DLL Hijacking vulnerability could allow a local attaEPSS 0.2%CVE-2022-36314MEDIUMWhen opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requEPSS 0.2%CVE-2025-10198HIGHLizardBytes Sunshine for Windows contains a DLL search-order hijacking vulnerabilityEPSS 0.2%CVE-2022-43722HIGHA vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software does not properly secure a folder containing lEPSS 0.2%CVE-2023-22358HIGHBIG-IP Edge Client for Windows vulnerabilityEPSS 0.2%CVE-2025-5981MEDIUMArbitrary File write in OSV-SCALIBREPSS 0.2%CVE-2022-26374HIGHUncontrolled search path in the installation binaries for Intel(R) SEAPI all versions may allow an authenticated user to potentially enable EPSS 0.2%CVE-2022-28696HIGHUncontrolled search path in the Intel(R) Distribution for Python before version 2022.0.3 may allow an authenticated user to potentially enabEPSS 0.2%CVE-2022-25841HIGHUncontrolled search path elements in the Intel(R) Datacenter Group Event Android application, all versions, may allow an authenticated user EPSS 0.2%