Falhas do tipo CWE-427

896 resultados

Caminho de busca ou elemento não controlado

A aplicação procura por um recurso (arquivo, biblioteca, módulo) em múltiplos diretórios sem validar ou controlar a ordem de busca, permitindo que um atacante injete um arquivo malicioso em um caminho que será verificado primeiro. Isso leva a execução de código não autorizado ou bypass de controles de segurança.

Exemplo

Um programa em C carrega uma biblioteca dinâmica (DLL no Windows ou SO no Linux) procurando em diretórios listados em uma variável de ambiente. Se o atacante conseguir escrever um arquivo malicioso com o mesmo nome em um diretório anterior da busca (como o diretório atual), a aplicação carrega a versão maliciosa sem questionar.

Como mitigar

Use caminhos absolutos e hardcoded para recursos críticos; nunca confie em variáveis de ambiente para localizá-los. Valide hash ou assinatura digital de bibliotecas carregadas e restrinja permissões de escrita nos diretórios de busca apenas ao administrador.

CVE-2025-34423HIGHMailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAIAU.DLLEPSS 0.2%CVE-2025-11772MEDIUMCo-Installer Privilege EscalationEPSS 0.2%CVE-2025-9000HIGHMechrevo Control Center GX V2 reg File uncontrolled search pathEPSS 0.2%CVE-2024-33672HIGHAn issue was discovered in Veritas NetBackup before 10.4. The Multi-Threaded Agent used in NetBackup can be leveraged to perform arbitrary fEPSS 0.2%CVE-2025-9016HIGHMechrevo Control Center GX V2 Powershell Script Command uncontrolled search pathEPSS 0.2%CVE-2025-34419HIGHMailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAISM.DLLEPSS 0.2%CVE-2025-34418HIGHMailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAIMF.DLLEPSS 0.2%CVE-2024-2637HIGHInsecure Loading of Code in B&R ProductsEPSS 0.2%CVE-2026-91803HIGHSecurity Vulnerability Report – Foxit PDF Editor/Reader Updater DLL Search Path HijackingEPSS 0.2%CVE-2025-9201HIGHA potential DLL hijacking vulnerability was discovered in Lenovo Browser during an internal security assessment that could allow a local useEPSS 0.2%CVE-2025-49148HIGHClipShare Server Allows Local Privilege Escalation via DLL HijackingEPSS 0.2%CVE-2024-55543HIGHLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) beforEPSS 0.2%CVE-2026-3787HIGHUltraVNC Windows Service cryptbase.dll uncontrolled search pathEPSS 0.2%CVE-2024-2208HIGHSound Research SECOMN64 Escalation of PrivilegeEPSS 0.2%CVE-2026-26050HIGHThe installer for ジョブログ集計/分析ソフトウェア RICOHジョブログ集計ツール versions prior to Ver.1.3.7 contains an issue with the DLL search path, which may lead toEPSS 0.2%CVE-2025-64995MEDIUMPrivilege Escalation via Process Hijacking in 1E-Exchange-NomadClientHealth-ConfigureGeneralSetting instructionEPSS 0.2%CVE-2026-50773HIGHAn issue in CGM Germany - CompuGroup Medical CGM ISIS MED 2510.1.0.20 allows a remote attacker to execute arbtirary code via a crafted .dll EPSS 0.2%CVE-2022-27187MEDIUMUncontrolled search path element in the Intel(R) Quartus Prime Standard edition software before version 21.1 Patch 0.02std may allow an authEPSS 0.2%CVE-2024-26017MEDIUMUncontrolled search path in some Intel(R) Rendering Toolkit software before version 2024.1.0 may allow an authenticated user to potentially EPSS 0.2%CVE-2025-53395HIGHParamount Macrium Reflect through 2025-06-26 allows local attackers to execute arbitrary code with administrator privileges via a crafted .mEPSS 0.2%