← Back
CWE-427

1,189 CVEs • Abstraction: Base

Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

JSON object

Loading...

CVEs (1,189)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Comodo
1Comodo Internet Security
Jun 17, 2026
Nov 18, 2019
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
An issue was discovered in signmgr.dll 6.5.0.819 in Comodo Internet Security through 12.0. A DLL Preloading vulnerability allows an attacker to implant an unsigned DLL named iLog.dll in a partially unprotected product di...Show more
An issue was discovered in signmgr.dll 6.5.0.819 in Comodo Internet Security through 12.0. A DLL Preloading vulnerability allows an attacker to implant an unsigned DLL named iLog.dll in a partially unprotected product directory. This DLL is then loaded into a high-privileged service before the binary signature validation logic is loaded, and might bypass some of the self-defense mechanisms.Show less
1Symantec
1Endpoint Protection
Jun 17, 2026
Nov 15, 2019
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
Symantec Endpoint Protection, prior to 14.2 RU2, may be susceptible to an unsigned code execution vulnerability, which may allow an individual to execute code without a resident proper digital signature.
1Adobe
1Illustrator Cc
Jun 17, 2026
Nov 14, 2019
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Adobe Illustrator CC versions 23.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.
1Adobe
1Animate Cc
Jun 17, 2026
Nov 14, 2019
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Adobe Animate CC versions 19.2.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.
1Nvidia
2Geforce Experience
Gpu Driver
Jun 17, 2026
Nov 12, 2019
N/A· v4
6.5 MEDIUM· v3
6.9 MEDIUM· v2
NVIDIA GeForce Experience (prior to 3.20.1) and Windows GPU Display Driver (all versions) contains a vulnerability in the local service provider component in which an attacker with local system and privileged access can...Show more
NVIDIA GeForce Experience (prior to 3.20.1) and Windows GPU Display Driver (all versions) contains a vulnerability in the local service provider component in which an attacker with local system and privileged access can incorrectly load Windows system DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), which may lead to denial of service or information disclosure through code execution.Show less
1Nvidia
1Geforce Experience
Jun 17, 2026
Nov 9, 2019
N/A· v4
7.8 HIGH· v3
6.2 MEDIUM· v2
NVIDIA GeForce Experience, all versions prior to 3.20.0.118, contains a vulnerability when GameStream is enabled in which an attacker with local system access can load the Intel graphics driver DLLs without validating th...Show more
NVIDIA GeForce Experience, all versions prior to 3.20.0.118, contains a vulnerability when GameStream is enabled in which an attacker with local system access can load the Intel graphics driver DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), which may lead to denial of service, information disclosure, or escalation of privileges through code execution.Show less
1Nvidia
1Gpu Driver
Jun 17, 2026
Nov 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.4 MEDIUM· v2
NVIDIA Windows GPU Display Driver, R390 driver version, contains a vulnerability in NVIDIA Control Panel in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as a binary...Show more
NVIDIA Windows GPU Display Driver, R390 driver version, contains a vulnerability in NVIDIA Control Panel in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), which may lead to denial of service or information disclosure through code execution. The attacker requires local system access.Show less
1Fortinet
1Forticlient
Jun 17, 2026
Oct 24, 2019
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
A malicious DLL preload vulnerability in Fortinet FortiClient for Windows 6.2.0 and below allows a privileged attacker to perform arbitrary code execution via forging that DLL.
2Avas!t
Avg
2Anti Virus
Antivirus
Jun 17, 2026
Oct 23, 2019
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
An issue was discovered in Avast antivirus before 19.8 and AVG antivirus before 19.8. A DLL Preloading vulnerability allows an attacker to implant %WINDIR%\system32\wbemcomn.dll, which is loaded into a protected-light pr...Show more
An issue was discovered in Avast antivirus before 19.8 and AVG antivirus before 19.8. A DLL Preloading vulnerability allows an attacker to implant %WINDIR%\system32\wbemcomn.dll, which is loaded into a protected-light process (PPL) and might bypass some of the self-defense mechanisms. This affects all components that use WMI, e.g., AVGSvc.exe 19.6.4546.0 and TuneupSmartScan.dll 19.1.884.0.Show less
1Trendmicro
1Anti Threat Toolkit
Jun 17, 2026
Oct 21, 2019
N/A· v4
7.8 HIGH· v3
5.1 MEDIUM· v2
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution...Show more
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed.Show less
1Nsa
1Ghidra
Jun 17, 2026
Oct 16, 2019
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
NSA Ghidra before 9.0.2 is vulnerable to DLL hijacking because it loads jansi.dll from the current working directory.
1Hp
1Touchpoint Analytics
Jun 17, 2026
Oct 11, 2019
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A potential security vulnerability has been identified with certain versions of HP Touchpoint Analytics prior to version 4.1.4.2827. This vulnerability may allow a local attacker with administrative privileges to execute...Show more
A potential security vulnerability has been identified with certain versions of HP Touchpoint Analytics prior to version 4.1.4.2827. This vulnerability may allow a local attacker with administrative privileges to execute arbitrary code via an HP Touchpoint Analytics system service.Show less
1Dell
2Encryption
Endpoint Security Suite Enterprise
Jun 17, 2026
Oct 7, 2019
N/A· v4
7.3 HIGH· v3
6.9 MEDIUM· v2
The vulnerability is limited to the installers of Dell Encryption Enterprise versions prior to 10.4.0 and Dell Endpoint Security Suite Enterprise versions prior to 2.4.0. This issue is exploitable only during the install...Show more
The vulnerability is limited to the installers of Dell Encryption Enterprise versions prior to 10.4.0 and Dell Endpoint Security Suite Enterprise versions prior to 2.4.0. This issue is exploitable only during the installation of the product by an administrator. A local authenticated low privileged user potentially could exploit this vulnerability by staging a malicious DLL in the search path of the installer prior to its execution by a local administrator. This would cause loading of the malicious DLL, which would allow the attacker to execute arbitrary code in the context of an administrator.Show less
1Jetbrains
1Resharper
Jun 17, 2026
Oct 2, 2019
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
JetBrains ReSharper installers for versions before 2019.2 had a DLL Hijacking vulnerability.
1Dell
1Update Package Framework
Jun 17, 2026
Sep 24, 2019
N/A· v4
6.7 MEDIUM· v3
6.2 MEDIUM· v2
An Uncontrolled Search Path Vulnerability is applicable to the following: Dell Update Package (DUP) Framework file versions prior to 19.1.0.413, and Framework file versions prior to 103.4.6.69 used in Dell EMC Servers. D...Show more
An Uncontrolled Search Path Vulnerability is applicable to the following: Dell Update Package (DUP) Framework file versions prior to 19.1.0.413, and Framework file versions prior to 103.4.6.69 used in Dell EMC Servers. Dell Update Package (DUP) Framework file versions prior to 3.8.3.67 used in Dell Client Platforms. The vulnerability is limited to the DUP framework during the time window when a DUP is being executed by an administrator. During this time window, a locally authenticated low privilege malicious user potentially could exploit this vulnerability by tricking an administrator into running a trusted binary, causing it to load a malicious DLL and allowing the attacker to execute arbitrary code on the victim system. The vulnerability does not affect the actual binary payload that the DUP delivers.Show less
1Adobe
1Application Manager
Jun 17, 2026
Sep 12, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Adobe application manager installer version 10.0 have an Insecure Library Loading (DLL hijacking) vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user.
1Eclipse
1Omr
Jun 17, 2026
Sep 12, 2019
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Prior to 0.1, AIX builds of Eclipse OMR contain unused RPATHs which may facilitate code injection and privilege elevation by local users.
1Ibm
1Db2 High Performance Unload Load
Jun 17, 2026
Aug 26, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum_debug is a setuid root binary which trusts the PATH environment variable. A low privileged user can ex...Show more
IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum_debug is a setuid root binary which trusts the PATH environment variable. A low privileged user can execute arbitrary commands as root by altering the PATH variable to point to a user controlled location. When a crash is induced the trojan gdb command is executed. IBM X-Force ID: 163488.Show less
1Autodesk
11Advance Steel
AutocadAutocad Architecture+8 more
Jun 17, 2026
Aug 23, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
DLL preloading vulnerability in versions 2017, 2018, 2019, and 2020 of Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, Au...Show more
DLL preloading vulnerability in versions 2017, 2018, 2019, and 2020 of Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D and version 2017 of AutoCAD P&ID. An attacker may trick a user into opening a malicious DWG file that may leverage a DLL preloading vulnerability in AutoCAD which may result in code execution.Show less
1Autodesk
1Design Review
Jun 17, 2026
Aug 23, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a DLL preloading vulnerability, which may resul...Show more
DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a DLL preloading vulnerability, which may result in code execution.Show less