CWE-427
1,189 CVEs • Abstraction: Base
Uncontrolled Search Path Element
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
CVEs (1,189)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Trendmicro 1Anti Threat Toolkit Jun 17, 2026 Jan 30, 2020 N/A· v4 7.8 HIGH· v3 5.1 MEDIUM· v2 Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution...Show more |
1Hexagongeospatial 1Erdas Er Viewer Nov 21, 2024 Jan 30, 2020 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 ERDAS ER Viewer 13.0 has dwmapi.dll and irml.dll libraries arbitrary code execution vulnerabilities |
In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attacker's copy of api-ms-win-core-path-l1-1-0.dll being loaded and...Show more |
1Schneider Electric 1Msx Configurator Jun 17, 2026 Jan 22, 2020 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 A CWE-427:Uncontrolled Search Path Element vulnerability exists in MSX Configurator (Software Version prior to V1.0.8.1), which could cause privilege escalation when injecting a malicious DLL. |
1Intel 1Snmp Subagent Stand Alone Jun 17, 2026 Jan 17, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Uncontrolled search path element in the installer for Intel(R) SNMP Subagent Stand-Alone for Windows* may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Symantec 1Norton Download Manager Nov 21, 2024 Jan 14, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A vulnerability was found in Symantec Norton Download Manager versions prior to 5.6. A remote user can create a specially crafted DLL file that, when placed on the target user's system, will cause the Norton Download Man...Show more |
1Symantec 9Endpoint Protection Endpoint Protection CloudNorton 360+6 moreNov 21, 2024 Jan 9, 2020 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 A Privilege Escalation vulnerability exists in Symantec Norton Antivirus, Norton AntiVirus with Backup, Norton Security, Norton Security with Backup, Norton Internet Security, Norton 360, Endpoint Protection Small Busine...Show more |
Signal Desktop before 1.29.1 on Windows allows local users to gain privileges by creating a Trojan horse %SYSTEMDRIVE%\node_modules\.bin\wmic.exe file. |
1Vmware 2Horizon View Agent WorkstationJun 17, 2026 Dec 23, 2019 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL hijacking vulnerability due to insecure loading of a DLL by Cortado Thinprint. Successful e...Show more |
1Trendmicro 1Housecall For Home Networks Jun 17, 2026 Dec 18, 2019 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 Trend Micro HouseCall for Home Networks (versions below 5.3.0.1063) could be exploited via a DLL Hijack related to a vulnerability on the packer that the program uses. |
AsLdrSrv.exe in ASUS ATK Package before V1.0.0061 (for Windows 10 notebook PCs) could lead to unsigned code execution with no additional execution. The user must put an application at a particular path, with a particular...Show more |
In the Quick Access Service (QAAdminAgent.exe) in Acer Quick Access V2.01.3000 through 2.01.3027 and V3.00.3000 through V3.00.3008, a REGULAR user can load an arbitrary unsigned DLL into the signed service's process, whi...Show more |
DLL Search Order Hijacking vulnerability in the Microsoft Windows client in McAfee Tech Check 3.0.0.17 and earlier allows local users to execute arbitrary code via the local folder placed there by an attacker. |
Dell Command Configure versions prior to 4.2.1 contain an uncontrolled search path vulnerability. A locally authenticated malicious user could exploit this vulnerability by creating a symlink to a target file, allowing t...Show more |
1Sony 2Catalyst Browse Catalyst Production SuiteJun 17, 2026 Dec 4, 2019 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 A weak malicious user can escalate its privilege whenever CatalystProductionSuite.2019.1.exe (version 1.1.0.21) and CatalystBrowseSuite.2019.1.exe (version 1.1.0.21) installers run. The vulnerability is in the form of DL...Show more |
COPA-DATA zenone32 zenon Editor through 8.10 has an Uncontrolled Search Path Element. |
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files...Show more |
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files...Show more |
DLL preloading vulnerability in Autodesk Desktop Application versions 7.0.16.29 and earlier. An attacker may trick a user into downloading a malicious DLL file into the working directory, which may then leverage a DLL pr...Show more |
1Cisco 2Webex Meetings Webex TeamsJun 17, 2026 Nov 26, 2019 N/A· v4 5.3 MEDIUM· v3 4.4 MEDIUM· v2 A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Webex Teams for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability,...Show more |