Falhas do tipo CWE-427

896 resultados

Caminho de busca ou elemento não controlado

A aplicação procura por um recurso (arquivo, biblioteca, módulo) em múltiplos diretórios sem validar ou controlar a ordem de busca, permitindo que um atacante injete um arquivo malicioso em um caminho que será verificado primeiro. Isso leva a execução de código não autorizado ou bypass de controles de segurança.

Exemplo

Um programa em C carrega uma biblioteca dinâmica (DLL no Windows ou SO no Linux) procurando em diretórios listados em uma variável de ambiente. Se o atacante conseguir escrever um arquivo malicioso com o mesmo nome em um diretório anterior da busca (como o diretório atual), a aplicação carrega a versão maliciosa sem questionar.

Como mitigar

Use caminhos absolutos e hardcoded para recursos críticos; nunca confie em variáveis de ambiente para localizá-los. Valide hash ou assinatura digital de bibliotecas carregadas e restrinja permissões de escrita nos diretórios de busca apenas ao administrador.

CVE-2022-25841HIGHUncontrolled search path elements in the Intel(R) Datacenter Group Event Android application, all versions, may allow an authenticated user EPSS 0.2%CVE-2025-49571HIGHSubstance3D - Modeler | Uncontrolled Search Path Element (CWE-427)EPSS 0.2%CVE-2023-32646MEDIUMUncontrolled search path element in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enaEPSS 0.2%CVE-2026-5055HIGHNoMachine Uncontrolled Search Path Element Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2022-27180MEDIUMUncontrolled search path in the Intel(R) MacCPUID software before version 3.2 may allow an authenticated user to potentially enable escalatiEPSS 0.2%CVE-2024-7061MEDIUMOkta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows vEPSS 0.2%CVE-2025-1131HIGHAsterisk Unsafe Shell Sourcing in safe_asterisk Leads to Local Privilege EscalationEPSS 0.2%CVE-2022-32972HIGHInfoblox BloxOne Endpoint for Windows through 2.2.7 allows DLL injection that can result in local privilege escalation.EPSS 0.2%CVE-2023-0213HIGHLocal Elevation of Privilege in M-FilesEPSS 0.2%CVE-2023-3662HIGHCODESYS: Vulnerability in CODESYS Development System allows for execution of binariesEPSS 0.2%CVE-2023-31016HIGHCVEEPSS 0.2%CVE-2026-76199HIGHPhotoshop Desktop | Uncontrolled Search Path Element (CWE-427)EPSS 0.2%CVE-2026-4546HIGHFlos Freeware Notepad2 TextShaping.dll uncontrolled search pathEPSS 0.2%CVE-2025-4539HIGHHainan ToDesk DLL File Parser profapi.dll uncontrolled search pathEPSS 0.2%CVE-2022-41796HIGHUntrusted search path vulnerability in the installer of Content Transfer (for Windows) Ver.1.3 and prior allows an attacker to gain privilegEPSS 0.2%CVE-2021-3423HIGHPrivilege escalation in Bitdefender GravityZone Business SecurityEPSS 0.2%CVE-2024-10093HIGHVSO ConvertXtoDvd ConvertXtoDvd.exe uncontrolled search pathEPSS 0.2%CVE-2026-42171HIGHNSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing locEPSS 0.2%CVE-2026-0487HIGHDLL Hijacking vulnerability in SAProuter on Microsoft WindowsEPSS 0.2%CVE-2023-6338HIGHUncontrolled search path vulnerabilities were reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local aEPSS 0.2%