Falhas do tipo CWE-427

897 resultados

Caminho de busca ou elemento não controlado

A aplicação procura por um recurso (arquivo, biblioteca, módulo) em múltiplos diretórios sem validar ou controlar a ordem de busca, permitindo que um atacante injete um arquivo malicioso em um caminho que será verificado primeiro. Isso leva a execução de código não autorizado ou bypass de controles de segurança.

Exemplo

Um programa em C carrega uma biblioteca dinâmica (DLL no Windows ou SO no Linux) procurando em diretórios listados em uma variável de ambiente. Se o atacante conseguir escrever um arquivo malicioso com o mesmo nome em um diretório anterior da busca (como o diretório atual), a aplicação carrega a versão maliciosa sem questionar.

Como mitigar

Use caminhos absolutos e hardcoded para recursos críticos; nunca confie em variáveis de ambiente para localizá-los. Valide hash ou assinatura digital de bibliotecas carregadas e restrinja permissões de escrita nos diretórios de busca apenas ao administrador.

CVE-2026-11967HIGHArbitrary code execution in MobaXterm Personal Edition (Portable)EPSS 0.1%CVE-2026-11879HIGHArbitrary code execution in MobaXterm Personal Edition (Portable)EPSS 0.1%CVE-2026-21661HIGHAC2000 Uncontrolled Search Path ElementEPSS 0.1%CVE-2025-14599MEDIUMQuartus® Prime Standard and Quartus® Prime Lite Security AdvisoryEPSS 0.1%CVE-2026-19590HIGHOpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations trusted the repositoEPSS 0.1%CVE-2025-14605MEDIUMQuartus Prime Pro Edition AdvisoryEPSS 0.1%CVE-2025-14596MEDIUMQuartus Prime Pro Edition Installer AdvisoryEPSS 0.1%CVE-2025-9164HIGHMultiple DLL Search Order Hijacking Vulnerabilities in Docker Desktop Installer for WindowsEPSS 0.1%CVE-2026-11958HIGHLocal privilege escalation in ANSSI’s DFIR-ORCEPSS 0.1%CVE-2024-22451MEDIUMDell Peripheral Manager, versions from 1.5.1 to 1.7.2, contain an uncontrolled search path element vulnerability. An attacker could potentiaEPSS 0.1%CVE-2024-22447MEDIUMDell Peripheral Manager, versions prior to 1.7.3, contain an uncontrolled search path element vulnerability. An attacker could potentially eEPSS 0.1%CVE-2025-32452MEDIUMUncontrolled search path for some AI Playground before version 2.6.1 beta within Ring 3: User Applications may allow an escalation of privilEPSS 0.1%CVE-2025-14575LOWUncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loadingEPSS 0.1%CVE-2026-20772MEDIUMUncontrolled search path for some Intel(R) Connectivity Performance Suite software installers before version 50.25.1121.193 within Ring 3: UEPSS 0.1%CVE-2025-36515MEDIUMUncontrolled search path for some AI Playground software before version 3.0.0 alpha within Ring 3: User Applications may allow an escalationEPSS 0.1%CVE-2025-35969MEDIUMUncontrolled search path for some Intel(R) Server Firmware Update Utility Software before version 16.0.12. within Ring 3: User Applications EPSS 0.1%CVE-2026-89325HIGHRapid7 Insight Agent: Uncontrolled search path element in InsightVM assessment content leads to local privilege escalationEPSS —