Falhas do tipo CWE-427

896 resultados

Caminho de busca ou elemento não controlado

A aplicação procura por um recurso (arquivo, biblioteca, módulo) em múltiplos diretórios sem validar ou controlar a ordem de busca, permitindo que um atacante injete um arquivo malicioso em um caminho que será verificado primeiro. Isso leva a execução de código não autorizado ou bypass de controles de segurança.

Exemplo

Um programa em C carrega uma biblioteca dinâmica (DLL no Windows ou SO no Linux) procurando em diretórios listados em uma variável de ambiente. Se o atacante conseguir escrever um arquivo malicioso com o mesmo nome em um diretório anterior da busca (como o diretório atual), a aplicação carrega a versão maliciosa sem questionar.

Como mitigar

Use caminhos absolutos e hardcoded para recursos críticos; nunca confie em variáveis de ambiente para localizá-los. Valide hash ou assinatura digital de bibliotecas carregadas e restrinja permissões de escrita nos diretórios de busca apenas ao administrador.

CVE-2024-37130HIGHDell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains a Local Privilege Escalation vulnerability via XSL Hijacking. A EPSS 0.2%CVE-2022-44744LOWLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Home Office (WindoEPSS 0.2%CVE-2022-32576MEDIUMUncontrolled search path in the Intel(R) Unite(R) Plugin SDK before version 4.2 may allow an authenticated user to potentially enable escalaEPSS 0.2%CVE-2025-10214HIGHDLL search path hijacking vulnerabilityEPSS 0.2%CVE-2022-41628MEDIUMUncontrolled search path element in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1EPSS 0.2%CVE-2025-10213HIGHDLL search path hijacking vulnerabilityEPSS 0.2%CVE-2023-24016MEDIUMUncontrolled search path element in some Intel(R) Quartus(R) Prime Pro and Standard edition software for linux may allow an authenticated usEPSS 0.2%CVE-2025-10215HIGHDLL search path hijacking vulnerabilityEPSS 0.2%CVE-2022-41693MEDIUMUncontrolled search path in the Intel(R) Quartus(R) Prime Pro edition software before version 22.3 may allow an authenticated user to potentEPSS 0.2%CVE-2022-34848MEDIUMUncontrolled search path for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enablEPSS 0.2%CVE-2023-34355MEDIUMUncontrolled search path element for some Intel(R) Server Board M10JNP2SB integrated BMC video drivers before version 3.0 for Microsoft WindEPSS 0.2%CVE-2022-38101MEDIUMUncontrolled search path in some Intel(R) NUC Chaco Canyon BIOS update software before version iFlashV Windows 5.13.00.2105 may allow an autEPSS 0.2%CVE-2023-28823MEDIUMUncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticatEPSS 0.2%CVE-2024-45246HIGHDiebold Nixdorf – CWE-427: Uncontrolled Search Path ElementEPSS 0.2%CVE-2023-23577MEDIUMUncontrolled search path element for some ITE Tech consumer infrared drivers before version 5.5.2.1 for Intel(R) NUC may allow an authenticaEPSS 0.2%CVE-2022-41982MEDIUMUncontrolled search path element in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentEPSS 0.2%CVE-2022-41998MEDIUMUncontrolled search path in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation ofEPSS 0.2%CVE-2024-34016MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (WindoEPSS 0.2%CVE-2022-43474MEDIUMUncontrolled search path for the DSP Builder software installer before version 22.4 for Intel(R) FPGAs Pro Edition may allow an authenticateEPSS 0.2%CVE-2025-34423HIGHMailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAIAU.DLLEPSS 0.2%