Falhas do tipo CWE-427

897 resultados

Caminho de busca ou elemento não controlado

A aplicação procura por um recurso (arquivo, biblioteca, módulo) em múltiplos diretórios sem validar ou controlar a ordem de busca, permitindo que um atacante injete um arquivo malicioso em um caminho que será verificado primeiro. Isso leva a execução de código não autorizado ou bypass de controles de segurança.

Exemplo

Um programa em C carrega uma biblioteca dinâmica (DLL no Windows ou SO no Linux) procurando em diretórios listados em uma variável de ambiente. Se o atacante conseguir escrever um arquivo malicioso com o mesmo nome em um diretório anterior da busca (como o diretório atual), a aplicação carrega a versão maliciosa sem questionar.

Como mitigar

Use caminhos absolutos e hardcoded para recursos críticos; nunca confie em variáveis de ambiente para localizá-los. Valide hash ou assinatura digital de bibliotecas carregadas e restrinja permissões de escrita nos diretórios de busca apenas ao administrador.

CVE-2025-12852HIGHDLL Loading vulnerability in NEC Corporation RakurakuMusen Start EX All Verisons allows a attacker to manipulate the PC environment to causeEPSS 0.1%CVE-2025-20092MEDIUMUncontrolled search path for some Clock Jitter Tool software before version 6.0.1 may allow an authenticated user to potentially enable escaEPSS 0.1%CVE-2024-28046MEDIUMUncontrolled search path in some Intel(R) GPA software before version 2024.1 may allow an authenticated user to potentially enable escalatioEPSS 0.1%CVE-2024-34017MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before buiEPSS 0.1%CVE-2024-34019MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before buiEPSS 0.1%CVE-2025-27717MEDIUMUncontrolled search path for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enable escalation of privEPSS 0.1%CVE-2024-26027MEDIUMUncontrolled search path for some Intel(R) Simics Package Manager software before version 1.8.3 may allow an authenticated user to potentialEPSS 0.1%CVE-2026-92838HIGHGeoVision GV-Remote E-Map dll hijacking vulnerabilityEPSS 0.1%CVE-2023-52945HIGHUncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local useEPSS 0.1%CVE-2025-0041HIGHUncontrolled search paths in the Vitis™ Embedded Single File Download (SFD) for local Windows installation could allow a low-privileged userEPSS 0.1%CVE-2025-13919MEDIUMComponent Object Model (COM) Hijacking in Symantec Endpoint Protection Windows ClientEPSS 0.1%CVE-2025-40763HIGHA vulnerability has been identified in Altair Grid Engine (All versions < V2026.0.0). Affected products do not properly validate environmentEPSS 0.1%CVE-2026-36574HIGHA DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and execute arbitrary codEPSS 0.1%CVE-2026-40004MEDIUMopenssl.cnf Privilege Escalation Vulnerability in ZTE Cloud PC Client uSmartviewEPSS 0.1%CVE-2025-48503HIGHA DLL hijacking vulnerability in the AMD Software Installer could allow an attacker to achieve privilege escalation potentially resulting inEPSS 0.1%CVE-2024-2207MEDIUMSound Research SECOMN64 Escalation of PrivilegeEPSS 0.1%CVE-2026-22270MEDIUMDell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an uncontrolled search path element vulneEPSS 0.1%CVE-2025-0712HIGHAPM Server Uncontrolled Search Path Element can lead to Local Privilege Escalation (LPE) when using the Windows InstallerEPSS 0.1%CVE-2025-12046HIGHA DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a local authenticated usEPSS 0.1%CVE-2026-87530HIGHUncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to exeEPSS 0.1%