Falhas do tipo CWE-427

895 resultados

Caminho de busca ou elemento não controlado

A aplicação procura por um recurso (arquivo, biblioteca, módulo) em múltiplos diretórios sem validar ou controlar a ordem de busca, permitindo que um atacante injete um arquivo malicioso em um caminho que será verificado primeiro. Isso leva a execução de código não autorizado ou bypass de controles de segurança.

Exemplo

Um programa em C carrega uma biblioteca dinâmica (DLL no Windows ou SO no Linux) procurando em diretórios listados em uma variável de ambiente. Se o atacante conseguir escrever um arquivo malicioso com o mesmo nome em um diretório anterior da busca (como o diretório atual), a aplicação carrega a versão maliciosa sem questionar.

Como mitigar

Use caminhos absolutos e hardcoded para recursos críticos; nunca confie em variáveis de ambiente para localizá-los. Valide hash ou assinatura digital de bibliotecas carregadas e restrinja permissões de escrita nos diretórios de busca apenas ao administrador.

CVE-2025-30672MEDIUMMite for Perl generates code with an untrusted search path vulnerabilityEPSS 0.4%CVE-2022-34900HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.3 (39313) Agent. An attacEPSS 0.4%CVE-2025-33208HIGHNVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled search path. A successful exploiEPSS 0.4%CVE-2019-25268HIGHNREL BEopt 2.8.0 Insecure Library Loading Arbitrary Code ExecutionEPSS 0.4%CVE-2025-30673MEDIUMSub::HandlesVia for Perl allows untrusted code to be included from the current working directoryEPSS 0.4%CVE-2025-3051MEDIUMLinux::Statm::Tiny for Perl allows untrusted code to be included from the current working directoryEPSS 0.4%CVE-2019-6564GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to place malicious files within the installer file directorEPSS 0.4%CVE-2021-36216LINE for Windows 6.2.1.2289 and before allows arbitrary code execution via malicious DLL injection.EPSS 0.4%CVE-2026-54916HIGHNetBox Device Type Library: Module Shadowing Bypass of prior pickle fix - RCE via missing `tests/__init__.py` + SSRF via unfixed `NETBOX_DT_LIBRARY_URL` → Cloud Metadata credential theftEPSS 0.4%CVE-2025-33122HIGHIBM i privilege escalationEPSS 0.4%CVE-2020-6654HIGHDLL HijackingEPSS 0.4%CVE-2024-30376HIGHFamatech Advanced IP Scanner Uncontrolled Search Path Element Local Privilege Escalation VulnerabilityEPSS 0.4%CVE-2017-11158Multiple untrusted search path vulnerabilities in the installer in Synology Cloud Station Drive before 4.2.5-4396 on Windows allow local attEPSS 0.4%CVE-2026-28456HIGHOpenClaw 2026.1.5 < 2026.2.14 - Arbitrary Code Execution via Unsafe Hook Module Path HandlingEPSS 0.4%CVE-2023-0247HIGHUncontrolled Search Path Element in bits-and-blooms/bloomEPSS 0.4%CVE-2023-26266HIGHIn AFL++ 4.05c, the CmpLog component uses the current working directory to resolve and execute unprefixed fuzzing targets, allowing code exeEPSS 0.4%CVE-2023-30237HIGHCyberGhostVPN Windows Client before v8.3.10.10015 was discovered to contain a DLL injection vulnerability via the component Dashboard.exe.EPSS 0.4%CVE-2025-22458HIGHDLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated attacker to escalate to EPSS 0.4%CVE-2021-1237HIGHCisco AnyConnect Secure Mobility Client for Windows DLL Injection VulnerabilityEPSS 0.4%CVE-2022-46330HIGHSquirrel.Windows is both a toolset and a library that provides installation and update functionality for Windows desktop applications. InstaEPSS 0.4%