CWE-426
655 CVEs • Abstraction: Base • Likelihood of Exploit: High
Untrusted Search Path
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
CVEs (655)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation. |
1Mcafee 1Host Intrusion Prevention Jun 17, 2026 Jun 10, 2020 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 DLL Search Order Hijacking Vulnerability in the installer component of McAfee Host Intrusion Prevention System (Host IPS) for Windows prior to 8.0.0 Patch 15 Update allows attackers with local access to execute arbitrary...Show more |
A symbolic link vulnerability in some Lenovo installation packages, prior to version 1.2.9.3, could allow privileged file operations during file extraction and installation. |
A DLL search path vulnerability could allow privilege escalation in some Lenovo installation packages, prior to version 1.2.9.3, during installation if an attacker already has administrative privileges. |
An issue was discovered in Foxit PhantomPDF before 8.3.6. It has an untrusted search path that allows a DLL to execute remote code. |
1Foxitsoftware 1Foxit Studio Photo Jun 17, 2026 Jun 4, 2020 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 An issue was discovered in Foxit Studio Photo before 3.6.6.922. It allows local users to gain privileges via a crafted DLL in the current working directory when FoxitStudioPhoto366_3.6.6.916.exe is used. |
1Foxitsoftware 1Foxit Studio Photo Jun 17, 2026 Jun 4, 2020 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 An issue was discovered in Foxit Studio Photo before 3.6.6.922. It allows local users to gain privileges via a crafted DLL in the current working directory. |
The file editing functionality in the Atlassian Companion App before version 1.0.0 allows local attackers to have the app run a different executable in place of the app's cmd.exe via a untrusted search path vulnerability...Show more |
1Schneider Electric 1Vijeo Designer Jun 17, 2026 Apr 22, 2020 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 A CWE-426: Untrusted Search Path vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 15 and prior) and Vijeo Designer (V6.9 SP9 and prior), which could cause arbitrary code execution on the system running Vijeo Bas...Show more |
Untrusted Search Path vulnerability in the windows installer of Google Earth Pro versions prior to 7.3.3 allows an attacker to insert malicious local files to execute unauthenticated remote code on the targeted system. |
An improper signature validation vulnerability in Autodesk Dynamo BIM versions 2.5.1 and 2.5.0 may lead to code execution through maliciously crafted DLL files. |
1Intel 1Binary Configuration Tool Jun 17, 2026 Apr 15, 2020 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 Uncontrolled search path in the installer for the Intel(R) Binary Configuration Tool for Windows, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Bitdefender 1Antimalware Software Development Kit Jun 17, 2026 Apr 7, 2020 N/A· v4 5.3 MEDIUM· v3 4.6 MEDIUM· v2 Untrusted Search Path vulnerability in Bitdefender High-Level Antimalware SDK for Windows allows an attacker to load third party code from a DLL library in the search path. This issue affects: Bitdefender High-Level Anti...Show more |
An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner 8.0.3 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded. |
1Mcafee 1Application And Change Control Jun 17, 2026 Mar 26, 2020 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 DLL Side Loading vulnerability in the installer for McAfee Application and Change Control (MACC) prior to 8.3 allows local users to execute arbitrary code via execution from a compromised folder. |
1Schneider Electric 1Ulti Zigbee Installation Toolkit Jun 17, 2026 Mar 23, 2020 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 A CWE-426: Untrusted Search Path vulnerability exists in ZigBee Installation Kit (Versions prior to 1.0.1), which could cause execution of malicious code when a malicious file is put in the search path. |
An untrusted search path vulnerability in the installer of PDFescape Desktop version 4.0.22 and earlier allows an attacker to gain privileges and execute code via DLL hijacking. |
An issue was discovered in IDM UltraEdit through 24.10.0.32. To exploit the vulnerability, on unpatched Windows systems, an attacker could include in the same directory as the affected executable a DLL using the name of...Show more |
3Canonical FedoraprojectOpensmtpd3Fedora OpensmtpdUbuntu LinuxJun 17, 2026 Feb 25, 2020 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in...Show more |
1Goverlan 3Client Agent Reach ConsoleReach ServerJun 17, 2026 Feb 16, 2020 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Command Injection and Local Privilege Escalation via DLL hijacki...Show more |