← Back
CWE-426

655 CVEs • Abstraction: Base • Likelihood of Exploit: High

Untrusted Search Path

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

JSON object

Loading...

CVEs (655)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
2365 Apps
Office Long Term Servicing Channel
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Microsoft Office Remote Code Execution Vulnerability
-
-
Jun 17, 2026
Oct 2, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
A potential security vulnerability has been identified in the HP One Agent for certain HP PC products, which might allow for escalation of privilege. HP is releasing software updates to mitigate this potential vulnerabil...Show more
A potential security vulnerability has been identified in the HP One Agent for certain HP PC products, which might allow for escalation of privilege. HP is releasing software updates to mitigate this potential vulnerability.Show less
1Intelbras
1Incontrol Web
Jun 17, 2026
Sep 29, 2024
8.5 HIGH· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability classified as critical has been found in Intelbras InControl up to 2.21.56. This affects an unknown part of the file C:\Program Files (x86)\Intelbras\Incontrol Cliente\incontrol_webcam\incontrol-service-w...Show more
A vulnerability classified as critical has been found in Intelbras InControl up to 2.21.56. This affects an unknown part of the file C:\Program Files (x86)\Intelbras\Incontrol Cliente\incontrol_webcam\incontrol-service-watchdog.exe. The manipulation leads to unquoted search path. It is possible to launch the attack on the local host. Upgrading to version 2.21.58 is able to address this issue. It is recommended to upgrade the affected component. The vendor was informed early on 2024-08-05 about this issue. The release of a fixed version 2.21.58 was announced for the end of August 2024 but then was postponed until 2024-09-20.Show less
-
-
Jun 17, 2026
Sep 26, 2024
8.4 HIGH· v4
6.7 MEDIUM· v3
N/A· v2
A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious authen...Show more
A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious authenticated attacker to elevate from a medium integrity process to a high integrity process without the intervention of a UAC prompt.Show less
1Ivanti
1Workspace Control
Jun 17, 2026
Sep 10, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.
1Sap
1Businessobjects Business Intelligence Platform
Jun 17, 2026
Sep 10, 2024
N/A· v4
5.8 MEDIUM· v3
N/A· v2
SAP BusinessObjects Business Intelligence Platform allows a high privilege user to run client desktop applications even if some of the DLLs are not digitally signed or if the signature is broken. The attacker needs to ha...Show more
SAP BusinessObjects Business Intelligence Platform allows a high privilege user to run client desktop applications even if some of the DLLs are not digitally signed or if the signature is broken. The attacker needs to have local access to the vulnerable system to perform DLL related tasks. This could result in a high impact on confidentiality and integrity of the application.Show less
1Yandex
1Yandex Browser
Jun 17, 2026
Sep 3, 2024
8.4 HIGH· v4
7.8 HIGH· v3
N/A· v2
Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.
1Br Automation
1Industrial Automation Aprol
Jun 17, 2026
Aug 29, 2024
5.4 MEDIUM· v4
7.8 HIGH· v3
N/A· v2
An untrusted search path vulnerability in B&R APROL <= R 4.4-00P3 may be used by an authenticated local attacker to get other users to execute arbitrary code under their privileges.
1Br Automation
1Industrial Automation Aprol
Jun 17, 2026
Aug 29, 2024
7.3 HIGH· v4
7.8 HIGH· v3
N/A· v2
An untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL <= R 4.2.-07P3 and <= R 4.4-00P3 may allow an authenticated local attacker to execute arbitrary code with elevated privileges.
1Dell
1Supportassist For Home Pcs
Jun 17, 2026
Aug 21, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
Dell SupportAssist for Home PCs Installer exe version 4.0.3 contains a privilege escalation vulnerability in the installer. A local low-privileged authenticated attacker could potentially exploit this vulnerability, lead...Show more
Dell SupportAssist for Home PCs Installer exe version 4.0.3 contains a privilege escalation vulnerability in the installer. A local low-privileged authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary executables on the operating system with elevated privileges.Show less
-
-
Jun 17, 2026
Aug 16, 2024
8.5 HIGH· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability has been found in Scooter Software Beyond Compare up to 3.3.5.15075 and classified as critical. Affected by this vulnerability is an unknown functionality in the library 7zxa.dll. The manipulation leads t...Show more
A vulnerability has been found in Scooter Software Beyond Compare up to 3.3.5.15075 and classified as critical. Affected by this vulnerability is an unknown functionality in the library 7zxa.dll. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The real existence of this vulnerability is still doubted at the moment. The vendor explains that a system must be breached before exploiting this issue. They are not planning on making any changes to address it.Show less
1Zoom
2Meeting Software Development Kit
Workplace Desktop
Jun 17, 2026
Aug 14, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Untrusted search path in the installer for Zoom Workplace Desktop App for macOS and Zoom Meeting SDK for macOS before 6.1.0 may allow a privileged user to conduct an escalation of privilege via local access.
1Adobe
1Dimension
Jun 17, 2026
Aug 14, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Dimension versions 3.4.11 and earlier are affected by an Untrusted Search Path vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by inserting a malicious file into th...Show more
Dimension versions 3.4.11 and earlier are affected by an Untrusted Search Path vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by inserting a malicious file into the search path, which the application might execute instead of the legitimate file. This could occur if the application uses a search path to locate executables or libraries. Exploitation of this issue requires user interaction.Show less
1Catonetworks
1Cato Client
Jun 17, 2026
Jul 31, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Cato Networks Windows SDP Client Local Privilege Escalation via openssl configuration file. This issue affects SDP Client before 5.10.34.
1Catonetworks
1Cato Client
Jun 17, 2026
Jul 31, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Cato Networks Windows SDP Client Local Privilege Escalation via self-upgradeThis issue affects SDP Client: before 5.10.34.
1Adobe
1Premiere Pro
Jun 17, 2026
Jul 9, 2024
N/A· v4
7.0 HIGH· v3
N/A· v2
Premiere Pro versions 23.6.5, 24.4.1 and earlier are affected by an Untrusted Search Path vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by inserting a malicious f...Show more
Premiere Pro versions 23.6.5, 24.4.1 and earlier are affected by an Untrusted Search Path vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by inserting a malicious file into the search path, which the application might execute instead of the legitimate file. This could occur when the application uses a search path to locate executables or libraries. Exploitation of this issue requires user interaction, attack complexity is high.Show less
1Microsoft
1Power Platform
Jul 20, 2026
Jun 27, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.
1Samsung
1Magician
Jun 17, 2026
Jun 20, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Samsung Magician 8.0.0 on Windows allows an admin to escalate privileges by tampering with the directory and DLL files used during the installation process. This occurs because of an Untrusted Search Path.
1Intelbras
1Incontrol
Jun 17, 2026
Jun 17, 2024
8.5 HIGH· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability classified as critical was found in Intelbras InControl 2.21.56. This vulnerability affects unknown code of the component incontrolWebcam Service. The manipulation leads to unquoted search path. Local acc...Show more
A vulnerability classified as critical was found in Intelbras InControl 2.21.56. This vulnerability affects unknown code of the component incontrolWebcam Service. The manipulation leads to unquoted search path. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Upgrading to version 2.21.58 is able to address this issue. It is recommended to upgrade the affected component. The vendor was contacted early about this disclosure and plans to provide a solution within the next few weeks.Show less
1Irods
1Irods
Jun 17, 2026
Jun 16, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the mailMS.cpp#L94-L106 reference.