Falhas do tipo CWE-427

896 resultados

Caminho de busca ou elemento não controlado

A aplicação procura por um recurso (arquivo, biblioteca, módulo) em múltiplos diretórios sem validar ou controlar a ordem de busca, permitindo que um atacante injete um arquivo malicioso em um caminho que será verificado primeiro. Isso leva a execução de código não autorizado ou bypass de controles de segurança.

Exemplo

Um programa em C carrega uma biblioteca dinâmica (DLL no Windows ou SO no Linux) procurando em diretórios listados em uma variável de ambiente. Se o atacante conseguir escrever um arquivo malicioso com o mesmo nome em um diretório anterior da busca (como o diretório atual), a aplicação carrega a versão maliciosa sem questionar.

Como mitigar

Use caminhos absolutos e hardcoded para recursos críticos; nunca confie em variáveis de ambiente para localizá-los. Valide hash ou assinatura digital de bibliotecas carregadas e restrinja permissões de escrita nos diretórios de busca apenas ao administrador.

CVE-2024-55540MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) beforEPSS 0.2%CVE-2025-53395HIGHParamount Macrium Reflect through 2025-06-26 allows local attackers to execute arbitrary code with administrator privileges via a crafted .mEPSS 0.2%CVE-2025-14498HIGHTradingView Desktop Electron Uncontrolled Search Path Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2025-1223MEDIUMAn attacker can gain application privileges in order to perform limited modification and/or read arbitrary dataEPSS 0.2%CVE-2025-55671HIGHUncontrolled search path element issue exists in TkEasyGUI versions prior to v1.0.22. If this vulnerability is exploited, arbitrary code mayEPSS 0.2%CVE-2024-49390HIGHLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files (Windows) before buiEPSS 0.2%CVE-2025-14406HIGHSoda PDF Desktop Uncontrolled Search Path Element Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2026-2538HIGHFlos Freeware Notepad2 Msimg32.dll uncontrolled search pathEPSS 0.2%CVE-2023-32272HIGHUncontrolled search path in some Intel NUC Pro Software Suite Configuration Tool software installers before version 3.0.0.6 may allow an autEPSS 0.2%CVE-2026-18656HIGHExecutable Resolution from Untrusted Project Directory in Kiro IDE on WindowsEPSS 0.2%CVE-2025-10549MEDIUMDLL Hijacking in EfficientLab Controlio Leads to Local Privilege EscalationEPSS 0.2%CVE-2024-38387MEDIUMUncontrolled search path in the Intel(R) Graphics Driver installers for versions 15.40 and 15.45 may allow an authenticated user to potentiaEPSS 0.2%CVE-2025-40827HIGHA vulnerability has been identified in Siemens Software Center (All versions < V3.5), Solid Edge SE2025 (All versions < V225.0 Update 10). TEPSS 0.2%CVE-2026-44406MEDIUMDLL Hijacking Vulnerability in ZTE Cloud PC Client uSmartviewEPSS 0.2%CVE-2021-33064MEDIUMUncontrolled search path in the software installer for Intel(R) System Studio for all versions, may allow an authenticated user to potentialEPSS 0.2%CVE-2022-27638MEDIUMUncontrolled search path element in the Intel(R) Advanced Link Analyzer Pro before version 22.2 and Standard edition software before versionEPSS 0.2%CVE-2022-30548MEDIUMUncontrolled search path element in the Intel(R) Glorp software may allow an authenticated user to potentially enable escalation of privilegEPSS 0.2%CVE-2025-11223HIGHInstaller of Panasonic AutoDownloader version 1.2.8 contains an issue with the DLL search path, which may lead to loading a craftEPSS 0.2%CVE-2025-57781HIGHThe installers of DENSO TEN drive recorder viewer contain an issue with the DLL search path, which may lead to insecurely loading Dynamic LiEPSS 0.2%CVE-2026-41567HIGHDocker: `PUT /containers/{id}/archive` executes container binary on the hostEPSS 0.2%