CWE-427— Uncontrolled Search Path Element
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.— MITRE CWE catalog
1,197 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-427page 13 of 24
- CVE-2023-28407HIGHCVSS 6.7EG 7.82024-02-14
Uncontrolled search path in some Intel(R) XTU software before version 7.12.0.29 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-28596HIGHCVSS 7.8EG 7.82023-03-27
Zoom Client for IT Admin macOS installers before version 5.13.5 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability in an attack chain during the installation process to escalate…
- CVE-2023-28740MEDIUMCVSS 6.7EG 6.72023-11-14
Uncontrolled search path element in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-28745MEDIUMCVSS 6.7EG 6.72024-02-14
Uncontrolled search path in Intel(R) QSFP+ Configuration Utility software, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-28759HIGHCVSS 7.8EG 7.82023-03-23
An issue was discovered in Veritas NetBackup before 10.0 on Windows. A vulnerability in the way the client validates the path to a DLL prior to loading may allow a lower-level user to elevate privileges and compromise the system.
- CVE-2023-28823MEDIUMCVSS 6.7EG 6.72023-08-11
Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-28929HIGHCVSS 7.8EG 7.82023-06-26
Trend Micro Security 2021, 2022, and 2023 (Consumer) are vulnerable to a DLL Hijacking vulnerability which could allow an attacker to use a specific executable file as an execution and/or persistence mechanism which could execute a malicio…
- CVE-2023-29011HIGHCVSS 7.5EG 7.52023-04-25
Git for Windows, the Windows port of Git, ships with an executable called `connect.exe`, which implements a SOCKS5 proxy that can be used to connect e.g. to SSH servers via proxies when certain ports are blocked for outgoing connections. T…
- CVE-2023-29012HIGHCVSS 7.2EG 7.22023-04-25
Git for Windows is the Windows port of Git. Prior to version 2.40.1, any user of Git CMD who starts the command in an untrusted directory is impacted by an Uncontrolles Search Path Element vulnerability. Maliciously-placed `doskey.exe` wou…
- CVE-2023-29069HIGHCVSS 7.8EG 7.82023-11-22
A maliciously crafted DLL file can be forced to install onto a non-default location, and attacker can overwrite parts of the product with malicious DLLs. These files may then have elevated privileges leading to a Privilege Escalation vulne…
- CVE-2023-29151MEDIUMCVSS 6.7EG 6.72023-08-11
Uncontrolled search path element in some Intel(R) PSR SDK before version 1.0.0.20 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-29161MEDIUMCVSS 6.7EG 6.72023-11-14
Uncontrolled search path in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-29187HIGHCVSS 6.7EG 7.32023-04-11
A Windows user with basic user authorization can exploit a DLL hijacking attack in SapSetup (Software Installation Program) - version 9.0, resulting in a privilege escalation running code as administrator of the very same Windows PC. A suc…
- CVE-2023-29444MEDIUMCVSS 6.3EG 6.32024-01-10
An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM. Alternatively, they could host a trojanized version of the software …
- CVE-2023-29445HIGHCVSS 7.8EG 7.82024-01-10
An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM.
- CVE-2023-29504MEDIUMCVSS 6.7EG 6.72023-11-14
Uncontrolled search path element in some Intel(R) RealSense(TM) Dynamic Calibration software before version 2.13.1.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-30237HIGHCVSS 7.8EG 7.82023-05-09
CyberGhostVPN Windows Client before v8.3.10.10015 was discovered to contain a DLL injection vulnerability via the component Dashboard.exe.
- CVE-2023-3078HIGHCVSS 7.8EG 7.82023-08-17
An uncontrolled search path vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to execute code with elevated privileges.
- CVE-2023-3091HIGHCVSS 7.0EG 7.02023-06-04
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Captura up to 8.0.0. It has been declared as critical. This vulnerability affects unknown code in the library CRYPTBASE.dll. The manipulation leads to uncontrolled search path. A…
- CVE-2023-31016HIGHCVSS 7.3EG 7.32023-11-02
NVIDIA GPU Display Driver for Windows contains a vulnerability where an uncontrolled search path element may allow an attacker to execute arbitrary code, which may lead to code execution, denial of service, escalation of privileges, inform…
- CVE-2023-31027HIGHCVSS 8.2EG 8.22023-11-02
NVIDIA GPU Display Driver for Windows contains a vulnerability that allows Windows users with low levels of privilege to escalate privileges when an administrator is updating GPU drivers, which may lead to escalation of privileges.
- CVE-2023-31197MEDIUMCVSS 6.7EG 6.72023-05-12
Uncontrolled search path in the Intel(R) Trace Analyzer and Collector before version 2020 update 3 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-31210HIGHCVSS 8.8EG 8.82023-12-13
Usage of user controlled LD_LIBRARY_PATH in agent in Checkmk 2.2.0p10 up to 2.2.0p16 allows malicious Checkmk site user to escalate rights via injection of malicious libraries
- CVE-2023-31348HIGHCVSS 7.3EG 7.32024-08-13
A DLL hijacking vulnerability in AMD μProf could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
- CVE-2023-31358HIGHCVSS 7.3EG 7.32025-05-13
A DLL hijacking vulnerability in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
- CVE-2023-31361HIGHCVSS 7.3EG 7.32025-02-11
A DLL hijacking vulnerability in AMD Integrated Management Technology (AIM-T) Manageability Service could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
- CVE-2023-31543CRITICALCVSS 9.8EG 9.82023-06-30
A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted PyPI package to the chosen repository server.
- CVE-2023-32272HIGHCVSS 7.9EG 7.92024-01-19
Uncontrolled search path in some Intel NUC Pro Software Suite Configuration Tool software installers before version 3.0.0.6 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2023-3252MEDIUMCVSS 6.8EG 6.82023-08-29
An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges could alter logging variables to overwrite arbitrary files on the remote host with log data, which could lead to a denial o…
- CVE-2023-32618HIGHCVSS 6.7EG 7.82024-02-14
Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-32646HIGHCVSS 6.7EG 7.32024-02-14
Uncontrolled search path element in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-32660MEDIUMCVSS 6.7EG 6.72023-11-14
Uncontrolled search path in some Intel(R) NUC Kit NUC6i7KYK Thunderbolt(TM) 3 Firmware Update Tool installation software before version 46 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-33874MEDIUMCVSS 6.7EG 6.72023-11-14
Uncontrolled search path in some Intel(R) NUC 12 Pro Kits & Mini PCs - NUC12WS Intel(R) HID Event Filter Driver installation software before version 2.2.2.1 for Windows may allow an authenticated user to potentially enable escalation of pr…
- CVE-2023-34350MEDIUMCVSS 6.7EG 6.72023-11-14
Uncontrolled search path element in some Intel(R) XTU software before version 7.12.0.15 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-34355MEDIUMCVSS 6.7EG 6.72023-08-11
Uncontrolled search path element for some Intel(R) Server Board M10JNP2SB integrated BMC video drivers before version 3.0 for Microsoft Windows and before version 1.13.4 for linux may allow an authenticated user to potentially enable escal…
- CVE-2023-34430MEDIUMCVSS 6.7EG 6.72023-11-14
Uncontrolled search path in some Intel Battery Life Diagnostic Tool software before version 2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-35060HIGHCVSS 6.7EG 7.82024-02-14
Uncontrolled search path in some Intel(R) Battery Life Diagnostic Tool software before version 2.3.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-35192MEDIUMCVSS 6.7EG 6.72024-05-16
Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-35769HIGHCVSS 6.7EG 7.82024-02-14
Uncontrolled search path in some Intel(R) CIP software before version 2.4.10577 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-35897HIGHCVSS 8.4EG 8.42023-10-06
IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0 could allow a local user to execute arbitrary code on the system using a specially crafted file, caused by a DLL hijacking flaw. IBM X-F…
- CVE-2023-36344HIGHCVSS 7.8EG 7.82023-08-08
An issue in Diebold Nixdorf Vynamic View Console v.5.3.1 and before allows a local attacker to execute arbitrary code via not restricting the search path for required DLLs and not verifying the signature.
- CVE-2023-36493HIGHCVSS 6.7EG 7.82024-02-14
Uncontrolled search path in some Intel(R) SDK for OpenCL(TM) Applications software may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-3662HIGHCVSS 7.3EG 7.32023-08-03
In CODESYS Development System versions from 3.5.17.0 and prior to 3.5.19.20 a vulnerability allows for execution of binaries from the current working directory in the users context .
- CVE-2023-36853HIGHCVSS 7.8EG 7.82023-07-19
In Keysight Geolocation Server v2.4.2 and prior, a low privileged attacker could create a local ZIP file containing a malicious script in any location. The attacker could abuse this to load a DLL with SYSTEM privileges.
- CVE-2023-37490HIGHCVSS 7.6EG 7.62023-08-08
SAP Business Objects Installer - versions 420, 430, allows an authenticated attacker within the network to overwrite an executable file created in a temporary directory during the installation process. On replacing this executable with a m…
- CVE-2023-37849MEDIUMCVSS 6.5EG 6.52023-07-13
A DLL hijacking vulnerability in Panda Security VPN for Windows prior to version v15.14.8 allows attackers to execute arbitrary code via placing a crafted DLL file in the same directory as PANDAVPN.exe.
- CVE-2023-38566HIGHCVSS 6.7EG 7.82024-02-14
Uncontrolled search path in some Intel(R) ISPC software before version 1.21.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-39254MEDIUMCVSS 6.7EG 6.72024-03-01
Dell Update Package (DUP), Versions prior to 4.9.10 contain an Uncontrolled Search Path vulnerability. A malicious user with local access to the system could potentially exploit this vulnerability to run arbitrary code as admin.
- CVE-2023-39374HIGHCVSS 7.8EG 7.82023-09-03
ForeScout NAC SecureConnector version 11.2 - CWE-427: Uncontrolled Search Path Element
- CVE-2023-39929MEDIUMCVSS 6.7EG 6.72024-05-16
Uncontrolled search path in some Libva software maintained by Intel(R) before version 2.20.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
Map vulnerabilities like CWE-427 to your infrastructure
EchelonGraph correlates every CVE — across CWE-427 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →