Falhas do tipo CWE-427

896 resultados

Caminho de busca ou elemento não controlado

A aplicação procura por um recurso (arquivo, biblioteca, módulo) em múltiplos diretórios sem validar ou controlar a ordem de busca, permitindo que um atacante injete um arquivo malicioso em um caminho que será verificado primeiro. Isso leva a execução de código não autorizado ou bypass de controles de segurança.

Exemplo

Um programa em C carrega uma biblioteca dinâmica (DLL no Windows ou SO no Linux) procurando em diretórios listados em uma variável de ambiente. Se o atacante conseguir escrever um arquivo malicioso com o mesmo nome em um diretório anterior da busca (como o diretório atual), a aplicação carrega a versão maliciosa sem questionar.

Como mitigar

Use caminhos absolutos e hardcoded para recursos críticos; nunca confie em variáveis de ambiente para localizá-los. Valide hash ou assinatura digital de bibliotecas carregadas e restrinja permissões de escrita nos diretórios de busca apenas ao administrador.

CVE-2025-20041MEDIUMUncontrolled search path for some Intel(R) Graphics software for Intel(R) Arc™ graphics and Intel(R) Iris(R) Xe graphics before version 32.0EPSS 0.2%CVE-2026-28700MEDIUMUncontrolled search path for some EquiTriton before version f5ddbb5 within Ring 3: User Applications may allow an escalation of privilege. UEPSS 0.2%CVE-2025-52541HIGHA DLL hijacking vulnerability in Vivado could allow a local attacker to achieve privilege escalation, potentially resulting in arbitrary codEPSS 0.2%CVE-2026-21408MEDIUMbeat-access for Windows version 3.0.3 and prior contains an issue with the DLL search path, which may lead to insecurely loading Dynamic LinEPSS 0.2%CVE-2025-20079MEDIUMUncontrolled search path for some Intel(R) Advisor software may allow an authenticated user to potentially enable escalation of privilege viEPSS 0.2%CVE-2024-22376MEDIUMUncontrolled search path element in some installation software for Intel(R) Ethernet Adapter Driver Pack before version 28.3 may allow an auEPSS 0.2%CVE-2022-50808HIGHCoolerMaster MasterPlus 1.8.5 - 'MPService' Unquoted Service PathEPSS 0.2%CVE-2023-51710MEDIUMEMS SQL Manager 3.6.2 (build 55333) for Oracle allows DLL hijacking: a user can trigger the execution of arbitrary code every time the produEPSS 0.2%CVE-2023-2355MEDIUMLocal privilege escalation due to a DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before bEPSS 0.2%CVE-2024-47196MEDIUMA vulnerability has been identified in ModelSim (All versions < V2025.2), Questa (All versions < V2025.2). vsimk.exe in affected applicationEPSS 0.2%CVE-2024-47194MEDIUMA vulnerability has been identified in ModelSim (All versions < V2024.3), Questa (All versions < V2024.3). vish2.exe in affected applicationEPSS 0.2%CVE-2026-25264HIGHUncontrolled Search Path Element in Qualcomm Software CenterEPSS 0.2%CVE-2026-47937HIGHAcrobat Reader | Uncontrolled Search Path Element (CWE-427)EPSS 0.2%CVE-2025-62185MEDIUMIn Ankitects Anki before 25.02.5, a crafted shared deck can place a YouTube downloader executable in the media folder, and this is executed EPSS 0.2%CVE-2024-47195MEDIUMA vulnerability has been identified in ModelSim (All versions < V2024.3), Questa (All versions < V2024.3). gdb.exe in affected applications EPSS 0.2%CVE-2024-21784MEDIUMUncontrolled search path for some Intel(R) IPP Cryptography software before version 2021.11 may allow an authenticated user to potentially eEPSS 0.1%CVE-2026-6421HIGHMobatek MobaXterm Home Edition msimg32.dll uncontrolled search pathEPSS 0.1%CVE-2025-62776HIGHThe installer of WTW EAGLE (for Windows) 3.0.8.0 contains an issue with the DLL search path, which may lead to insecurely loading Dynamic LiEPSS 0.1%CVE-2024-23907MEDIUMUncontrolled search path in some Intel(R) High Level Synthesis Compiler software before version 23.4 may allow an authenticated user to poteEPSS 0.1%CVE-2025-64695HIGHUncontrolled search path element issue exists in the installer of LogStare Collector (for Windows). If exploited, arbitrary code may be execEPSS 0.1%