← Back
CWE-427

1,189 CVEs • Abstraction: Base

Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

JSON object

Loading...

CVEs (1,189)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
Jun 17, 2026
Apr 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. Certain security settings, related to whether packages are verified and accepted only from known sources, are mishandled....Show more
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. Certain security settings, related to whether packages are verified and accepted only from known sources, are mishandled. The LG ID is LVE-SMP-190002 (April 2019).Show less
1Lg
1Pc Suite
Jun 17, 2026
Apr 17, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
An issue was discovered in LG PC Suite for LG G3 and earlier (aka LG PC Suite v5.3.27 and earlier). DLL Hijacking can occur via a Trojan horse DLL in the current working directory. The LG ID is LVE-MOT-190001 (November 2...Show more
An issue was discovered in LG PC Suite for LG G3 and earlier (aka LG PC Suite v5.3.27 and earlier). DLL Hijacking can occur via a Trojan horse DLL in the current working directory. The LG ID is LVE-MOT-190001 (November 2019).Show less
1Starface
1Unified Communication & Collaboration Client
Jun 17, 2026
Apr 2, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-0006.
1Ui
1Unifi Video
Jun 17, 2026
Apr 1, 2020
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
In UniFi Video v3.10.1 (for Windows 7/8/10 x64) there is a Local Privileges Escalation to SYSTEM from arbitrary file deletion and DLL hijack vulnerabilities. The issue was fixed by adjusting the .tsExport folder when the...Show more
In UniFi Video v3.10.1 (for Windows 7/8/10 x64) there is a Local Privileges Escalation to SYSTEM from arbitrary file deletion and DLL hijack vulnerabilities. The issue was fixed by adjusting the .tsExport folder when the controller is running on Windows and adjusting the SafeDllSearchMode in the windows registry when installing UniFi-Video controller. Affected Products: UniFi Video Controller v3.10.2 (for Windows 7/8/10 x64) and prior. Fixed in UniFi Video Controller v3.10.3 and newer.Show less
1Adobe
2Acrobat Dc
Acrobat Reader Dc
Jun 17, 2026
Mar 25, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and 2015.006.30510 and earlier have an insecure library loading (dll hijac...Show more
Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and 2015.006.30510 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.Show less
1Asus
1Device Activation
Jun 17, 2026
Mar 25, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
DevActSvc.exe in ASUS Device Activation before 1.0.7.0 for Windows 10 notebooks and PCs could lead to unsigned code execution with no additional restrictions when a user puts an application at a particular path with a pa...Show more
DevActSvc.exe in ASUS Device Activation before 1.0.7.0 for Windows 10 notebooks and PCs could lead to unsigned code execution with no additional restrictions when a user puts an application at a particular path with a particular file name.Show less
1Schneider Electric
1Pmepxm0100 Prosoft Configurator
Jun 17, 2026
Mar 23, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProSoft Configurator (v1.002 and prior), for the PMEPXM0100 (H) module, which could cause the execution of untrusted code when using double click to ope...Show more
A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProSoft Configurator (v1.002 and prior), for the PMEPXM0100 (H) module, which could cause the execution of untrusted code when using double click to open a project file which may trigger execution of a malicious DLL.Show less
1Fortinet
2Forticlient
Forticlient Virtual Private Network
Jun 17, 2026
Mar 15, 2020
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may allow a local attacker with control over the directory in which FortiClientOnlineInstaller.exe and FortiClientVPNOnlineI...Show more
An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may allow a local attacker with control over the directory in which FortiClientOnlineInstaller.exe and FortiClientVPNOnlineInstaller.exe resides to execute arbitrary code on the system via uploading malicious Filter Library DLL files in that directory.Show less
1Fortinet
1Forticlient Emergency Management Server
Jun 17, 2026
Mar 15, 2020
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
An Unsafe Search Path vulnerability in FortiClient EMS online installer 6.2.1 and below may allow a local attacker with control over the directory in which FortiClientEMSOnlineInstaller.exe resides to execute arbitrary c...Show more
An Unsafe Search Path vulnerability in FortiClient EMS online installer 6.2.1 and below may allow a local attacker with control over the directory in which FortiClientEMSOnlineInstaller.exe resides to execute arbitrary code on the system via uploading malicious Filter Library DLL files in that directory.Show less
1Trendmicro
1Password Manager
Jun 17, 2026
Mar 12, 2020
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
Trend Micro Password Manager for Windows version 5.0 is affected by a DLL hijacking vulnerability would could potentially allow an attacker privleged escalation.
1Intel
1Graphics Driver
Jun 17, 2026
Mar 12, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Uncontrolled search path in Intel(R) Graphics Drivers before version 26.20.100.7158 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Graphics Driver
Jun 17, 2026
Mar 12, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Uncontrolled search path element in the installer for Intel(R) Graphics Drivers before versions 26.20.100.7584, 15.45.30.5103, 15.40.44.5107, 15.36.38.5117, and 15.33.49.5100 may allow an authenticated user to potentiall...Show more
Uncontrolled search path element in the installer for Intel(R) Graphics Drivers before versions 26.20.100.7584, 15.45.30.5103, 15.40.44.5107, 15.36.38.5117, and 15.33.49.5100 may allow an authenticated user to potentially enable escalation of privilege via local accessShow less
1Dell
113G3 15 3590 Firmware
G3 3579 FirmwareG3 3779 Firmware+110 more
Jun 17, 2026
Feb 21, 2020
N/A· v4
4.4 MEDIUM· v3
2.6 LOW· v2
Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is limited to the Dell Firmware Update Utility during the time window while being executed by an administ...Show more
Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is limited to the Dell Firmware Update Utility during the time window while being executed by an administrator. During this time window, a locally authenticated low-privileged malicious user could exploit this vulnerability by tricking an administrator into overwriting arbitrary files via a symlink attack. The vulnerability does not affect the actual binary payload that the update utility delivers.Show less
1Trendmicro
1Vulnerability Protection
Jun 17, 2026
Feb 20, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Trend Micro Vulnerability Protection 2.0 is affected by a vulnerability that could allow an attack to use the product installer to load other DLL files located in the same directory.
1Trendmicro
8Control Manager
Endpoint SensorIm Security+5 more
Jun 17, 2026
Feb 20, 2020
N/A· v4
7.0 HIGH· v3
5.1 MEDIUM· v2
Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installat...Show more
Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installation. The vulnerability was found to ONLY be exploitable during an initial product installation by an authorized user. The attacker must convince the target to download malicious DLL locally which must be present when the installer is run.Show less
1Cisco
1Anyconnect Secure Mobility Client
Jun 17, 2026
Feb 19, 2020
N/A· v4
6.5 MEDIUM· v3
4.9 MEDIUM· v2
A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level priv...Show more
A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. To exploit this vulnerability, the attacker needs valid credentials on the Windows system.Show less
1Westerndigital
2Sandiskssddashboardsetup.exe
Westerndigitalssddashboardsetup.exe
Jun 17, 2026
Feb 19, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking.
1Symantec
1Endpoint Protection
Jun 17, 2026
Feb 11, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a DLL injection vulnerability, w...Show more
Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a DLL injection vulnerability, which is a type of issue whereby an individual attempts to execute their own code in place of legitimate code as a means to perform an exploit.Show less
1Atlassian
2Confluence
Confluence Server
Jun 17, 2026
Feb 6, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a dir...Show more
The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a directory in the global path environmental variable variable to inject code & escalate their privileges via a DLL hijacking vulnerability.Show less
1Atlassian
1Jira Server
Jun 17, 2026
Feb 6, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directory in the global path environmental variable can inject code into via a DLL hijacking vulnerability.