← Back
CWE-427

1,189 CVEs • Abstraction: Base

Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

JSON object

Loading...

CVEs (1,189)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Huawei
1Hisuite
Jun 17, 2026
Jun 13, 2019
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
HiSuite 9.1.0.300 versions and earlier contains a DLL hijacking vulnerability. This vulnerability exists due to some DLL file is loaded by HiSuite improperly. And it allows an attacker to load this DLL file of the attack...Show more
HiSuite 9.1.0.300 versions and earlier contains a DLL hijacking vulnerability. This vulnerability exists due to some DLL file is loaded by HiSuite improperly. And it allows an attacker to load this DLL file of the attacker's choosing that could execute arbitrary code.Show less
1Htc
1Viveport
Jun 17, 2026
Jun 3, 2019
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Privilege escalation due to insecure directory permissions affecting ViveportDesktopService in HTC VIVEPORT before 1.0.0.36 allows local attackers to escalate privileges via DLL hijacking.
1Adobe
1Creative Cloud
Jun 17, 2026
May 24, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Creative Cloud Desktop Application (installer) versions 4.7.0.400 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.
1Pelco
1Videoxpert Opscenter
Jun 17, 2026
May 22, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A Uncontrolled Search Path Element (CWE-427) vulnerability exists in VideoXpert OpsCenter versions prior to 3.1 which could allow an attacker to cause the system to call an incorrect DLL.
1F Secure
5Client Security
Computer ProtectionInternet Security+2 more
Jun 17, 2026
May 17, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In the F-Secure installer in F-Secure SAFE for Windows before 17.6, F-Secure Internet Security before 17.6, F-Secure Anti-Virus before 17.6, F-Secure Client Security Standard and Premium before 14.10, F-Secure PSB Workst...Show more
In the F-Secure installer in F-Secure SAFE for Windows before 17.6, F-Secure Internet Security before 17.6, F-Secure Anti-Virus before 17.6, F-Secure Client Security Standard and Premium before 14.10, F-Secure PSB Workstation Security before 12.01, and F-Secure Computer Protection Standard and Premium before 19.3, a local user can escalate their privileges through a DLL hijacking attack against the installer. The installer writes the file rm.exe to C:\Windows\Temp and then executes it. The rm.exe process then attempts to load several DLLs from its current directory. Non-admin users are able to write to this folder, so an attacker can create a malicious C:\Windows\Temp\OLEACC.dll file. When an admin runs the installer, rm.exe will execute the attacker's DLL in an elevated security context.Show less
1Vmware
1Workstation
Jun 17, 2026
May 15, 2019
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
VMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are improperly loaded by the application. Successful exploitation of this issue may allow attackers with normal user privilege...Show more
VMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are improperly loaded by the application. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to administrator on a windows host where Workstation is installed.Show less
1Nvidia
2Geforce Experience
Gpu Display Driver
Jun 17, 2026
May 10, 2019
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as a binary planting o...Show more
NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), leading to escalation of privileges through code execution.Show less
1Ge
1Ge Communicator
Jun 17, 2026
May 9, 2019
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to place malicious files within the installer file directory, which may allow an attacker to gain administrative privileges on a system dur...Show more
GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to place malicious files within the installer file directory, which may allow an attacker to gain administrative privileges on a system during installation or upgrade.Show less
1Ge
1Ge Communicator
Jun 17, 2026
May 9, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
GE Communicator, all versions prior to 4.0.517, allows an attacker to place malicious files within the working directory of the program, which may allow an attacker to manipulate widgets and UI elements.
1Cisco
1Meeting Server
Jun 17, 2026
Apr 18, 2019
N/A· v4
5.1 MEDIUM· v3
3.6 LOW· v2
A vulnerability in the search path processing of Cisco Directory Connector could allow an authenticated, local attacker to load a binary of their choosing. The vulnerability is due to uncontrolled search path elements. A...Show more
A vulnerability in the search path processing of Cisco Directory Connector could allow an authenticated, local attacker to load a binary of their choosing. The vulnerability is due to uncontrolled search path elements. An attacker could exploit this vulnerability by placing a binary of their choosing earlier in the search path utilized by Cisco Directory Connector to locate and load required resources.Show less
1Gemalto
1Sentinel Ultrapro Client Library
Jun 17, 2026
Apr 11, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The uncontrolled search path element vulnerability in Gemalto Sentinel UltraPro Client Library ux32w.dll Versions 1.3.0, 1.3.1, and 1.3.2 enables an attacker to load and execute a malicious file.
1Schneider Electric
1Opc Factory Server
Nov 21, 2024
Mar 25, 2019
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory on servers running Schneider Electric OFS v3.5 with version v7.40 of SCADA Expert Vijeo Citect/Cite...Show more
A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory on servers running Schneider Electric OFS v3.5 with version v7.40 of SCADA Expert Vijeo Citect/CitectSCADA, OFS v3.5 with version v7.30 of Vijeo Citect/CitectSCADA, and OFS v3.5 with version v7.20 of Vijeo Citect/CitectSCADA.. If the application attempts to open that file, the application could crash or allow the attacker to execute arbitrary code. Schneider Electric recommends vulnerable users upgrade the OFS to V3.5 and install the latest service pack (SP 6 or newer) for their associated version.Show less
2Opensuse
Putty
3Backports Sle
LeapPutty
Jun 17, 2026
Mar 21, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same directory as the executable.
1Ibm
1Db2
Jun 17, 2026
Mar 21, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege user full access to root by loading a mal...Show more
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege user full access to root by loading a malicious shared library. IBM X-Force ID: 158014.Show less
1Ibm
1Sdk
Nov 21, 2024
Mar 11, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
IBM SDK, Java Technology Edition Version 8 on the AIX platform uses absolute RPATHs which may facilitate code injection and privilege elevation by local users. IBM X-Force ID: 152081.
1Golang
1Go
Jun 17, 2026
Mar 8, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Go through 1.12 on Windows misuses certain LoadLibrary functionality, leading to DLL injection.
1Solarwinds
1Orion Platform
Jun 17, 2026
Mar 1, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.
1Sublimetext
1Sublime Text 3
Jun 17, 2026
Feb 25, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
DLL hijacking is possible in Sublime Text 3 version 3.1.1 build 3176 on 32-bit Windows platforms because a Trojan horse api-ms-win-core-fibers-l1-1-1.dll or api-ms-win-core-localization-l1-2-1.dll file may be loaded if a...Show more
DLL hijacking is possible in Sublime Text 3 version 3.1.1 build 3176 on 32-bit Windows platforms because a Trojan horse api-ms-win-core-fibers-l1-1-1.dll or api-ms-win-core-localization-l1-2-1.dll file may be loaded if a victim uses sublime_text.exe to open a .txt file within an attacker's %LOCALAPPDATA%\Temp\sublime_text folder. NOTE: the vendor's position is "This does not appear to be a bug with Sublime Text, but rather one with Windows that has been patched.Show less
3Canonical
DebianRdflib Project
3Debian Linux
RdflibUbuntu Linux
Jun 17, 2026
Feb 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working directory, allowing code injection, because "python -m" looks in this directory, as demo...Show more
The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working directory, allowing code injection, because "python -m" looks in this directory, as demonstrated by rdf2dot. This issue is specific to use of the debian/scripts directory.Show less
1Ntt West
1Fall Creators Update
Nov 21, 2024
Jan 9, 2019
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Untrusted search path vulnerability in The installer of Windows 10 Fall Creators Update Modify module for Security Measures tool allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.