← Back
CWE-427

1,189 CVEs • Abstraction: Base

Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

JSON object

Loading...

CVEs (1,189)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Trendmicro
1Anti Threat Toolkit
Jun 17, 2026
Jan 30, 2020
N/A· v4
7.8 HIGH· v3
5.1 MEDIUM· v2
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution...Show more
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed. Another attack vector similar to CVE-2019-9491 was idenitfied and resolved in version 1.62.0.1228 of the tool.Show less
1Hexagongeospatial
1Erdas Er Viewer
Nov 21, 2024
Jan 30, 2020
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
ERDAS ER Viewer 13.0 has dwmapi.dll and irml.dll libraries arbitrary code execution vulnerabilities
1Python
1Python
Jun 17, 2026
Jan 28, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attacker's copy of api-ms-win-core-path-l1-1-0.dll being loaded and...Show more
In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attacker's copy of api-ms-win-core-path-l1-1-0.dll being loaded and used instead of the system's copy. Windows 8 and later are unaffected.Show less
1Schneider Electric
1Msx Configurator
Jun 17, 2026
Jan 22, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
A CWE-427:Uncontrolled Search Path Element vulnerability exists in MSX Configurator (Software Version prior to V1.0.8.1), which could cause privilege escalation when injecting a malicious DLL.
1Intel
1Snmp Subagent Stand Alone
Jun 17, 2026
Jan 17, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Uncontrolled search path element in the installer for Intel(R) SNMP Subagent Stand-Alone for Windows* may allow an authenticated user to potentially enable escalation of privilege via local access.
1Symantec
1Norton Download Manager
Nov 21, 2024
Jan 14, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A vulnerability was found in Symantec Norton Download Manager versions prior to 5.6. A remote user can create a specially crafted DLL file that, when placed on the target user's system, will cause the Norton Download Man...Show more
A vulnerability was found in Symantec Norton Download Manager versions prior to 5.6. A remote user can create a specially crafted DLL file that, when placed on the target user's system, will cause the Norton Download Manager component to load the remote user's DLL instead of the intended DLL and execute arbitrary code when the Norton Download Manager component is run by the target user.Show less
1Symantec
9Endpoint Protection
Endpoint Protection CloudNorton 360+6 more
Nov 21, 2024
Jan 9, 2020
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
A Privilege Escalation vulnerability exists in Symantec Norton Antivirus, Norton AntiVirus with Backup, Norton Security, Norton Security with Backup, Norton Internet Security, Norton 360, Endpoint Protection Small Busine...Show more
A Privilege Escalation vulnerability exists in Symantec Norton Antivirus, Norton AntiVirus with Backup, Norton Security, Norton Security with Backup, Norton Internet Security, Norton 360, Endpoint Protection Small Business Edition Cloud, and Endpoint Protection Cloud Client due to a DLL-preloading without path restrictions, which could let a local malicious user obtain system privileges.Show less
1Signal
1Signal Desktop
Jun 17, 2026
Dec 24, 2019
N/A· v4
7.3 HIGH· v3
6.9 MEDIUM· v2
Signal Desktop before 1.29.1 on Windows allows local users to gain privileges by creating a Trojan horse %SYSTEMDRIVE%\node_modules\.bin\wmic.exe file.
1Vmware
2Horizon View Agent
Workstation
Jun 17, 2026
Dec 23, 2019
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL hijacking vulnerability due to insecure loading of a DLL by Cortado Thinprint. Successful e...Show more
VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL hijacking vulnerability due to insecure loading of a DLL by Cortado Thinprint. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to administrator on a Windows machine where Workstation or View Agent is installed.Show less
1Trendmicro
1Housecall For Home Networks
Jun 17, 2026
Dec 18, 2019
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Trend Micro HouseCall for Home Networks (versions below 5.3.0.1063) could be exploited via a DLL Hijack related to a vulnerability on the packer that the program uses.
1Asus
1Atk Package
Jun 17, 2026
Dec 18, 2019
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
AsLdrSrv.exe in ASUS ATK Package before V1.0.0061 (for Windows 10 notebook PCs) could lead to unsigned code execution with no additional execution. The user must put an application at a particular path, with a particular...Show more
AsLdrSrv.exe in ASUS ATK Package before V1.0.0061 (for Windows 10 notebook PCs) could lead to unsigned code execution with no additional execution. The user must put an application at a particular path, with a particular file name.Show less
1Acer
1Quick Access
Jun 17, 2026
Dec 17, 2019
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
In the Quick Access Service (QAAdminAgent.exe) in Acer Quick Access V2.01.3000 through 2.01.3027 and V3.00.3000 through V3.00.3008, a REGULAR user can load an arbitrary unsigned DLL into the signed service's process, whi...Show more
In the Quick Access Service (QAAdminAgent.exe) in Acer Quick Access V2.01.3000 through 2.01.3027 and V3.00.3000 through V3.00.3008, a REGULAR user can load an arbitrary unsigned DLL into the signed service's process, which is running as NT AUTHORITY\SYSTEM. This is a DLL Hijacking vulnerability (including search order hijacking, which searches for the missing DLL in the PATH environment variable), which is caused by an uncontrolled search path element for nvapi.dll, atiadlxx.dll, or atiadlxy.dll.Show less
1Mcafee
1Techcheck
Jun 17, 2026
Dec 11, 2019
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
DLL Search Order Hijacking vulnerability in the Microsoft Windows client in McAfee Tech Check 3.0.0.17 and earlier allows local users to execute arbitrary code via the local folder placed there by an attacker.
1Dell
1Command|configure
Jun 17, 2026
Dec 6, 2019
N/A· v4
7.1 HIGH· v3
6.6 MEDIUM· v2
Dell Command Configure versions prior to 4.2.1 contain an uncontrolled search path vulnerability. A locally authenticated malicious user could exploit this vulnerability by creating a symlink to a target file, allowing t...Show more
Dell Command Configure versions prior to 4.2.1 contain an uncontrolled search path vulnerability. A locally authenticated malicious user could exploit this vulnerability by creating a symlink to a target file, allowing the attacker to overwrite or corrupt a specified file on the system.Show less
1Sony
2Catalyst Browse
Catalyst Production Suite
Jun 17, 2026
Dec 4, 2019
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
A weak malicious user can escalate its privilege whenever CatalystProductionSuite.2019.1.exe (version 1.1.0.21) and CatalystBrowseSuite.2019.1.exe (version 1.1.0.21) installers run. The vulnerability is in the form of DL...Show more
A weak malicious user can escalate its privilege whenever CatalystProductionSuite.2019.1.exe (version 1.1.0.21) and CatalystBrowseSuite.2019.1.exe (version 1.1.0.21) installers run. The vulnerability is in the form of DLL Hijacking. The installers try to load DLLs that don’t exist from its current directory; by doing so, an attacker can quickly escalate its privileges.Show less
1Copadata
1Zenon
Jun 17, 2026
Dec 4, 2019
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
COPA-DATA zenone32 zenon Editor through 8.10 has an Uncontrolled Search Path Element.
1Dell
1Command Update
Jun 17, 2026
Dec 3, 2019
N/A· v4
5.5 MEDIUM· v3
3.6 LOW· v2
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files...Show more
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\IC\ICDebugLog.txt" to any targeted file. This issue occurs because of insecure handling of Temp directory permissions that were set incorrectly.Show less
1Dell
1Command Update
Jun 17, 2026
Dec 3, 2019
N/A· v4
5.5 MEDIUM· v3
3.6 LOW· v2
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files...Show more
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\ICProgress\Dell_InventoryCollector_Progress.xml" to any targeted file. This issue occurs because permissions on the Temp directory were set incorrectly.Show less
1Autodesk
1Autodesk Desktop
Jun 17, 2026
Dec 3, 2019
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
DLL preloading vulnerability in Autodesk Desktop Application versions 7.0.16.29 and earlier. An attacker may trick a user into downloading a malicious DLL file into the working directory, which may then leverage a DLL pr...Show more
DLL preloading vulnerability in Autodesk Desktop Application versions 7.0.16.29 and earlier. An attacker may trick a user into downloading a malicious DLL file into the working directory, which may then leverage a DLL preloading vulnerability and execute code on the system.Show less
1Cisco
2Webex Meetings
Webex Teams
Jun 17, 2026
Nov 26, 2019
N/A· v4
5.3 MEDIUM· v3
4.4 MEDIUM· v2
A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Webex Teams for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability,...Show more
A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Webex Teams for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due to insufficient validation of the resources loaded by the application at run time. An attacker could exploit this vulnerability by crafting a malicious DLL file and placing it in a specific location on the targeted system. The malicious DLL file would execute when the vulnerable application is launched. A successful exploit could allow the attacker to execute arbitrary code on the target machine with the privileges of another user account.Show less