Falhas do tipo CWE-427

896 resultados

Caminho de busca ou elemento não controlado

A aplicação procura por um recurso (arquivo, biblioteca, módulo) em múltiplos diretórios sem validar ou controlar a ordem de busca, permitindo que um atacante injete um arquivo malicioso em um caminho que será verificado primeiro. Isso leva a execução de código não autorizado ou bypass de controles de segurança.

Exemplo

Um programa em C carrega uma biblioteca dinâmica (DLL no Windows ou SO no Linux) procurando em diretórios listados em uma variável de ambiente. Se o atacante conseguir escrever um arquivo malicioso com o mesmo nome em um diretório anterior da busca (como o diretório atual), a aplicação carrega a versão maliciosa sem questionar.

Como mitigar

Use caminhos absolutos e hardcoded para recursos críticos; nunca confie em variáveis de ambiente para localizá-los. Valide hash ou assinatura digital de bibliotecas carregadas e restrinja permissões de escrita nos diretórios de busca apenas ao administrador.

CVE-2026-9169HIGHLUCID Vision Labs: DLL Search Order Hijacking in Arena SDK 1.0.80.49 on WindowsEPSS 0.1%CVE-2026-34488HIGHIP Setting Software contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arEPSS 0.1%CVE-2024-28953MEDIUMUncontrolled search path in some EMON software before version 11.44 may allow an authenticated user to potentially enable escalation of privEPSS 0.1%CVE-2024-8766MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (WindoEPSS 0.1%CVE-2026-40031HIGHMemProcFS < 5.17 DLL/Shared Library HijackingEPSS 0.1%CVE-2026-92180HIGHpdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation VulnerabilityEPSS 0.1%CVE-2025-20050MEDIUMUncontrolled search path for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escEPSS 0.1%CVE-2026-47274MEDIUMpam_usb: Uncontrolled search path in pam_usb tools allows privilege escalation via PATH manipulationEPSS 0.1%CVE-2025-24842MEDIUMUncontrolled search path for the Intel(R) System Support Utility before version 4.1.0 within Ring 3: User Applications may allow an escalatiEPSS 0.1%CVE-2025-7676MEDIUMDLL hijacking of all PE32 executables on Windows 11 for ARM CPUsEPSS 0.1%CVE-2025-25011HIGHBeats Uncontrolled Search Path Element can lead to Local Privilege Escalation (LPE) when using the Windows InstallerEPSS 0.1%CVE-2026-6958HIGHAcunetix 25.11.251107123 Local Privilege Escalation via wvsc.exeEPSS 0.1%CVE-2024-29015MEDIUMUncontrolled search path in some Intel(R) VTune(TM) Profiler software before versions 2024.1 may allow an authenticated user to potentially EPSS 0.1%CVE-2024-28887MEDIUMUncontrolled search path in some Intel(R) IPP software before version 2021.11 may allow an authenticated user to potentially enable escalatiEPSS 0.1%CVE-2026-24694HIGHThe installer for Roland Cloud Manager ver.3.1.19 and prior insecurely loads Dynamic Link Libraries (DLLs), which could allow an attacker toEPSS 0.1%CVE-2024-34019MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before buiEPSS 0.1%CVE-2025-20092MEDIUMUncontrolled search path for some Clock Jitter Tool software before version 6.0.1 may allow an authenticated user to potentially enable escaEPSS 0.1%CVE-2025-40979HIGHDLL search order hijack in Wave by Grandstream NetworksEPSS 0.1%CVE-2025-26404MEDIUMUncontrolled search path for some Intel(R) DSA software before version 25.2.15.9 may allow an authenticated user to potentially enable escalEPSS 0.1%CVE-2026-92838HIGHGeoVision GV-Remote E-Map dll hijacking vulnerabilityEPSS 0.1%