Falhas do tipo CWE-427

894 resultados

Caminho de busca ou elemento não controlado

A aplicação procura por um recurso (arquivo, biblioteca, módulo) em múltiplos diretórios sem validar ou controlar a ordem de busca, permitindo que um atacante injete um arquivo malicioso em um caminho que será verificado primeiro. Isso leva a execução de código não autorizado ou bypass de controles de segurança.

Exemplo

Um programa em C carrega uma biblioteca dinâmica (DLL no Windows ou SO no Linux) procurando em diretórios listados em uma variável de ambiente. Se o atacante conseguir escrever um arquivo malicioso com o mesmo nome em um diretório anterior da busca (como o diretório atual), a aplicação carrega a versão maliciosa sem questionar.

Como mitigar

Use caminhos absolutos e hardcoded para recursos críticos; nunca confie em variáveis de ambiente para localizá-los. Valide hash ou assinatura digital de bibliotecas carregadas e restrinja permissões de escrita nos diretórios de busca apenas ao administrador.

CVE-2021-3613OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if preEPSS 0.8%CVE-2023-41117HIGHAn issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x beEPSS 0.8%CVE-2025-24039HIGHVisual Studio Code Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2025-29803HIGHVisual Studio Tools for Applications and SQL Server Management Studio Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2022-32168HIGHnotepad-plus-plus - DLL HijackingEPSS 0.7%CVE-2018-4938HIGHAdobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Insecure Library Loading vuEPSS 0.7%CVE-2026-34054HIGHopenssl on Windows built with openssldir set from the build machine (Uncontrolled Search Path Element)EPSS 0.7%CVE-2021-20051SonicWall Global VPN Client 4.10.7.1117 installer (32-bit and 64-bit) and earlier versions have a DLL Search Order Hijacking vulnerability iEPSS 0.7%CVE-2020-24419HIGHUncontrolled Search Path Element in Adobe After Effects for WindowsEPSS 0.7%CVE-2020-27348MEDIUMsnapcraft may build snaps with incorrect LD_LIBRARY_PATHEPSS 0.7%CVE-2017-14017An Uncontrolled Search Path Element issue was discovered in Progea Movicon Version 11.5.1181 and prior. An uncontrolled search path element EPSS 0.7%CVE-2025-21206HIGHVisual Studio Installer Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2026-40342CRITICALFirebird: Path Traversal + Arbitrary File Write Leads to Remote Code ExecutionEPSS 0.7%CVE-2020-9681MEDIUMAdobe Genuine Service privilege escalation vulnerabilityEPSS 0.7%CVE-2020-24425HIGHPrivilege escalation vulnerability in Dreamweaver version 20.2EPSS 0.7%CVE-2023-27298HIGHUncontrolled search path in the WULT software maintained by Intel(R) before version 1.0.0 (commit id 592300b) may allow an unauthenticated uEPSS 0.7%CVE-2024-5290HIGHAn issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attEPSS 0.7%CVE-2022-28688HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802EPSS 0.7%CVE-2022-28686HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802EPSS 0.6%CVE-2020-24440HIGHUncontrolled Search Path Element in Adobe Prelude for WindowsEPSS 0.6%