Falhas do tipo CWE-427

896 resultados

Caminho de busca ou elemento não controlado

A aplicação procura por um recurso (arquivo, biblioteca, módulo) em múltiplos diretórios sem validar ou controlar a ordem de busca, permitindo que um atacante injete um arquivo malicioso em um caminho que será verificado primeiro. Isso leva a execução de código não autorizado ou bypass de controles de segurança.

Exemplo

Um programa em C carrega uma biblioteca dinâmica (DLL no Windows ou SO no Linux) procurando em diretórios listados em uma variável de ambiente. Se o atacante conseguir escrever um arquivo malicioso com o mesmo nome em um diretório anterior da busca (como o diretório atual), a aplicação carrega a versão maliciosa sem questionar.

Como mitigar

Use caminhos absolutos e hardcoded para recursos críticos; nunca confie em variáveis de ambiente para localizá-los. Valide hash ou assinatura digital de bibliotecas carregadas e restrinja permissões de escrita nos diretórios de busca apenas ao administrador.

CVE-2023-42920HIGHClaris International has fixed a dylib hijacking vulnerability in the FileMaker Pro.app and Claris Pro.app versions on macOS.EPSS 0.2%CVE-2025-69784HIGHA local, non-privileged attacker can abuse a vulnerable IOCTL interface exposed by the OpenEDR 2.5.1.0 kernel driver to modify the DLL injecEPSS 0.2%CVE-2026-6645HIGHInsecure Search Path Vulnerability in PaperCut Print Deploy Client for WindowsEPSS 0.2%CVE-2023-29187MEDIUMDLL Hijacking vulnerability in SapSetup (Software Installation Program)EPSS 0.2%CVE-2024-21861MEDIUMUncontrolled search path in some Intel(R) GPA Framework software before version 2023.4 may allow an authenticated user to potentially enableEPSS 0.2%CVE-2024-34167MEDIUMUncontrolled search path for the Intel(R) Server Board S2600ST Family BIOS and Firmware Update software all versions may allow an authenticaEPSS 0.2%CVE-2025-0069HIGHDLL Hijacking vulnerability in SAPSetupEPSS 0.2%CVE-2022-33921HIGHDell GeoDrive, versions prior to 2.2, contains Multiple DLL Hijacking Vulnerabilities. A low privilege attacker could potentially exploit thEPSS 0.2%CVE-2025-11940HIGHLibreWolf Installer setup.nsi uncontrolled search pathEPSS 0.2%CVE-2023-45320MEDIUMUncontrolled search path element in some Intel(R) VTune(TM) Profiler software before version 2024.0 may allow an authenticated user to potenEPSS 0.2%CVE-2026-22561MEDIUMUncontrolled search path elements in Anthropic Claude for Windows installer (Claude Setup.exe) versions prior to 1.1.3363 allow local privilEPSS 0.2%CVE-2025-59889HIGHImproper authentication of library files in the Eaton IPP software installer could lead to arbitrary code execution of an attacker with the EPSS 0.2%CVE-2026-42936HIGHThe installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affeEPSS 0.2%CVE-2024-57964HIGHInsecure Loading of Dynamic Link Libraries in HVAC Energy Saving ProgramEPSS 0.2%CVE-2025-48496MEDIUMEmerson ValveLink Products Uncontrolled Search Path ElementEPSS 0.2%CVE-2025-11178HIGHLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before builEPSS 0.2%CVE-2023-28080MEDIUM PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains DLL Hijacking Vulnerabilities. A regular user (non-admin) can exploit these issues EPSS 0.2%CVE-2026-24317MEDIUMDLL Hijacking vulnerability in SAP GUI for Windows with active GuiXTEPSS 0.2%CVE-2024-57963HIGHInsecure Loading of Dynamic Link Libraries in USB-CONVERTERCABLE DRIVEREPSS 0.2%CVE-2025-57716MEDIUMAn Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versioEPSS 0.2%