CWE-427— Uncontrolled Search Path Element
1,094 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-427page 7 of 22
- CVE-2021-28822HIGHCVSS 8.8EG 8.82021-03-23
The Enterprise Message Service Server (tibemsd), Enterprise Message Service Central Administration (tibemsca), Enterprise Message Service JSON configuration generator (tibemsconf2json), and Enterprise Message Service C API components of TI…
- CVE-2021-28953HIGHCVSS 7.8EG 7.82021-03-21
The unofficial C/C++ Advanced Lint extension before 1.9.0 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a crafted repository.
- CVE-2021-28954HIGHCVSS 7.8EG 7.82021-03-21
In Chris Walz bit before 1.0.5 on Windows, attackers can run arbitrary code via a .exe file in a crafted repository.
- CVE-2021-28955CRITICALCVSS 9.8EG 9.82021-03-22
git-bug before 0.7.2 has an Uncontrolled Search Path Element. It will execute git.bat from the current directory in certain PATH situations (most often seen on Windows).
- CVE-2021-29949HIGHCVSS 7.8EG 7.82021-06-24
When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filename that isn't distributed by Thunderbird. If a computer has already been infected with a malicious l…
- CVE-2021-30359HIGHCVSS 7.8EG 7.82021-10-22
The Harmony Browse and the SandBlast Agent for Browsers installers must have admin privileges to execute some steps during the installation. Because the MS Installer allows regular users to repair their installation, an attacker running an…
- CVE-2021-30360HIGHCVSS 7.8EG 7.82022-01-10
Users have access to the directory where the installation repair occurs. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted EXE in the repair folder…
- CVE-2021-3041HIGHCVSS 7.8EG 7.82021-06-10
A local privilege escalation vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated local Windows user to execute programs with SYSTEM privileges. This requires the user to have t…
- CVE-2021-3042HIGHCVSS 7.8EG 7.82021-07-15
A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated local Windows user to execute programs with SYSTEM privileges. Exploiting this vulnerabili…
- CVE-2021-3115HIGHCVSS 7.5EG 7.52021-01-26
Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, cgo can execute a gcc program from an un…
- CVE-2021-31637HIGHCVSS 7.8EG 7.82023-03-16
An issue found in UwAmp v.1.1, 1.2, 1.3, 2.0, 2.1, 2.2, 2.2.1, 3.0.0, 3.0.1, 3.0.2 allows a remote attacker to execute arbitrary code via a crafted DLL.
- CVE-2021-31840HIGHCVSS 7.3EG 7.32021-06-10
A vulnerability in the preloading mechanism of specific dynamic link libraries in McAfee Agent for Windows prior to 5.7.3 could allow an authenticated, local attacker to perform a DLL preloading attack with unsigned DLLs. To exploit this v…
- CVE-2021-31847HIGHCVSS 8.2EG 7.82021-09-22
Improper access control vulnerability in the repair process for McAfee Agent for Windows prior to 5.7.4 could allow a local attacker to perform a DLL preloading attack using unsigned DLLs. This would result in elevation of privileges and t…
- CVE-2021-31853HIGHCVSS 7.8EG 7.82021-11-10
DLL Search Order Hijacking Vulnerability in McAfee Drive Encryption (MDE) prior to 7.3.0 HF2 (7.3.0.183) allows local users to execute arbitrary code and escalate privileges via execution from a compromised folder.
- CVE-2021-32466HIGHCVSS 7.0EG 7.02021-09-29
An uncontrolled search path element privilege escalation vulnerability in Trend Micro HouseCall for Home Networks version 5.3.1225 and below could allow an attacker to escalate privileges by placing a custom crafted file in a specific dire…
- CVE-2021-32580HIGHCVSS 7.8EG 7.82021-08-05
Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to DLL hijacking.
- CVE-2021-32592HIGHCVSS 7.8EG 7.82021-12-01
An unsafe search path vulnerability in FortiClientWindows 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x and FortiClientEMS 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x may allow an attacker to perform a DLL Hijack attack on affected devices via a malicious…
- CVE-2021-33064MEDIUMCVSS 6.7EG 7.82022-11-11
Uncontrolled search path in the software installer for Intel(R) System Studio for all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-33101HIGHCVSS 7.8EG 7.82022-02-09
Uncontrolled search path in the Intel(R) GPA software before version 21.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-3423HIGHCVSS 7.8EG 7.82021-05-18
Uncontrolled Search Path Element vulnerability in the openssl component as used in Bitdefender GravityZone Business Security allows an attacker to load a third party DLL to elevate privileges. This issue affects Bitdefender GravityZone Bus…
- CVE-2021-34606HIGHCVSS 7.3EG 7.32022-05-11
A vulnerability exists in XINJE XD/E Series PLC Program Tool in versions up to v3.5.1 that can allow an authenticated, local attacker to load a malicious DLL. Local access is required to successfully exploit this vulnerability. This means …
- CVE-2021-3464HIGHCVSS 7.8EG 7.82021-04-27
A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow privilege escalation.
- CVE-2021-34803HIGHCVSS 7.8EG 7.82021-06-16
TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations.
- CVE-2021-3550HIGHCVSS 7.8EG 7.82021-07-16
A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.500.5102, that could allow privilege escalation.
- CVE-2021-35957MEDIUMCVSS 6.7EG 6.72021-07-13
Stormshield Endpoint Security Evolution 2.0.0 through 2.0.2 does not accomplish the intended defense against local administrators who can replace the Visual C++ runtime DLLs (in %WINDIR%\system32) with malicious ones.
- CVE-2021-35982HIGHCVSS 7.3EG 7.32021-09-29
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Uncontrolled Search Path Element vulnerability. A local attacker with non-administrative privileges c…
- CVE-2021-3606HIGHCVSS 7.8EG 7.82021-07-02
OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main Ope…
- CVE-2021-3613HIGHCVSS 7.8EG 7.82021-07-02
OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN…
- CVE-2021-36216HIGHCVSS 7.8EG 7.82021-09-08
LINE for Windows 6.2.1.2289 and before allows arbitrary code execution via malicious DLL injection.
- CVE-2021-3633HIGHCVSS 7.3EG 7.82021-08-17
A DLL preloading vulnerability was reported in Lenovo Driver Management prior to version 2.9.0719.1104 that could allow privilege escalation.
- CVE-2021-36376HIGHCVSS 7.8EG 7.82021-07-13
dandavison delta before 0.8.3 on Windows resolves an executable's pathname as a relative path from the current directory.
- CVE-2021-36631MEDIUMCVSS 6.7EG 6.72022-12-22
Untrusted search path vulnerability in Baidunetdisk Version 7.4.3 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
- CVE-2021-36753HIGHCVSS 7.8EG 7.82021-07-15
sharkdp BAT before 0.18.2 executes less.exe from the current working directory.
- CVE-2021-36770HIGHCVSS 7.8EG 7.82021-08-11
Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::ConfigLocal library (in the current working directory) that preempts dynamic module loading. Exploitation requires an unusua…
- CVE-2021-37617HIGHCVSS 7.3EG 7.32021-08-18
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. The Nextcloud Desktop Client invokes its uninstaller script when being installed to make sure there are no remnants of previous installation…
- CVE-2021-38086HIGHCVSS 7.8EG 7.82021-08-12
Acronis Cyber Protect 15 for Windows prior to build 27009 and Acronis Agent for Windows prior to build 26226 allowed local privilege escalation via DLL hijacking.
- CVE-2021-3840HIGHCVSS 8.8EG 8.82021-11-12
A dependency confusion vulnerability was reported in the Antilles open-source software prior to version 1.0.1 that could allow for remote code execution during installation due to a package listed in requirements.txt not existing in the pu…
- CVE-2021-38410HIGHCVSS 7.3EG 7.82022-07-27
AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the s…
- CVE-2021-38416HIGHCVSS 7.8EG 7.82021-11-03
Delta Electronics DIALink versions 1.2.4.0 and prior insecurely loads libraries, which may allow an attacker to use DLL hijacking and takeover the system where the software is installed.
- CVE-2021-38420HIGHCVSS 7.8EG 7.82021-11-03
Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow an attacker to modify the installation directory and upload malicious files.
- CVE-2021-38469CRITICALCVSS 9.1EG 9.12021-10-22
Many of the services used by the affected product do not specify full paths for the DLLs they are loading. An attacker can exploit the uncontrolled search path by implanting their own DLL near the affected product’s binaries, thus hijack…
- CVE-2021-38571HIGHCVSS 7.8EG 7.82021-08-11
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows DLL hijacking, aka CNVD-C-2021-68000 and CNVD-C-2021-68502.
- CVE-2021-4007HIGHCVSS 7.8EG 7.82021-12-14
Rapid7 Insight Agent, versions 3.0.1 to 3.1.2.34, suffer from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when Insight Agent versions 3.0.1 to 3.1.2.34 start, the Python interpreter attempts to load p…
- CVE-2021-40161HIGHCVSS 7.8EG 7.82021-12-23
A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through PDFTron earlier than 9.0.7 version.
- CVE-2021-40981HIGHCVSS 7.3EG 7.32021-09-27
ASUS ROG Armoury Crate Lite before 4.2.10 allows local users to gain privileges by placing a Trojan horse file in the publicly writable %PROGRAMDATA%\ASUS\GamingCenterLib directory.
- CVE-2021-41544HIGHCVSS 7.8EG 7.82023-08-08
A vulnerability has been identified in Siemens Software Center (All versions < V3.0). A DLL Hijacking vulnerability could allow a local attacker to execute code with elevated privileges by placing a malicious DLL in one of the directories …
- CVE-2021-42101HIGHCVSS 7.8EG 7.82021-10-21
An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-p…
- CVE-2021-42102HIGHCVSS 7.8EG 7.82021-10-21
An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service agents could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execut…
- CVE-2021-42103HIGHCVSS 7.8EG 7.82021-10-21
An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-p…
- CVE-2021-42743HIGHCVSS 8.8EG 7.82022-05-06
A misconfiguration in the node default path allows for local privilege escalation from a lower privileged user to the Splunk user in Splunk Enterprise versions before 8.1.1 on Windows.
Map vulnerabilities like CWE-427 to your infrastructure
EchelonGraph correlates every CVE — across CWE-427 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →