← Back
CWE-427

1,189 CVEs • Abstraction: Base

Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

JSON object

Loading...

CVEs (1,189)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Feb 12, 2025
5.4 MEDIUM· v4
6.7 MEDIUM· v3
N/A· v2
Uncontrolled search path for some Intel(R) Chipset Software Installation Utility before version 10.1.19867.8574 may allow an authenticated user to potentially enable escalation of privilege via local access.
-
-
Jun 17, 2026
Feb 12, 2025
5.4 MEDIUM· v4
6.7 MEDIUM· v3
N/A· v2
Uncontrolled search path for the Intel(R) Thread Director Visualizer software before version 1.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
-
-
Jun 17, 2026
Feb 12, 2025
5.4 MEDIUM· v4
6.7 MEDIUM· v3
N/A· v2
Uncontrolled search path for some Intel(R) High Level Synthesis Compiler software before version 24.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
-
-
Jun 17, 2026
Feb 12, 2025
5.4 MEDIUM· v4
6.7 MEDIUM· v3
N/A· v2
Uncontrolled search path for some Intel(R) MPI Library for Windows software before version 2021.13 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Quickassist Technology
Jun 17, 2026
Feb 12, 2025
5.4 MEDIUM· v4
7.8 HIGH· v3
N/A· v2
Uncontrolled search path for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
-
-
Jun 17, 2026
Feb 12, 2025
5.4 MEDIUM· v4
6.7 MEDIUM· v3
N/A· v2
Uncontrolled search path in some Intel(R) Ethernet Adapter Complete Driver Pack install before versions 29.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
-
-
Jun 17, 2026
Feb 12, 2025
5.4 MEDIUM· v4
6.7 MEDIUM· v3
N/A· v2
Uncontrolled search path in some Intel(R) VPL software before version 2023.4.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
-
-
Jun 17, 2026
Feb 11, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
A DLL hijacking vulnerability in AMD Integrated Management Technology (AIM-T) Manageability Service could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
1Microsoft
1Visual Studio Code
Jun 17, 2026
Feb 11, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
Visual Studio Code Elevation of Privilege Vulnerability
1Microsoft
3Visual Studio 2017
Visual Studio 2019Visual Studio 2022
Jun 17, 2026
Feb 11, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
Visual Studio Installer Elevation of Privilege Vulnerability
1Siemens
2Modelsim
Questa
Jun 17, 2026
Feb 11, 2025
5.4 MEDIUM· v4
7.8 HIGH· v3
N/A· v2
A vulnerability has been identified in ModelSim (All versions < V2025.1), Questa (All versions < V2025.1). An example setup script contained in affected applications allows a specific executable file to be loaded from th...Show more
A vulnerability has been identified in ModelSim (All versions < V2025.1), Questa (All versions < V2025.1). An example setup script contained in affected applications allows a specific executable file to be loaded from the current working directory. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges in installations where administrators or processes with elevated privileges launch the script from a user-writable directory.Show less
-
-
Jun 17, 2026
Feb 7, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Tally Prime Edit Log v2.1 was discovered to contain a DLL hijacking vulnerability via the component TextShaping.dll. This vulnerability allows attackers to execute arbitrary code via a crafted DLL.
-
-
Jun 17, 2026
Feb 6, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a malicious DLL in a directory where the application loads dependencies. This vulnerability arises due to...Show more
NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a malicious DLL in a directory where the application loads dependencies. This vulnerability arises due to the improper validation of dynamically loaded libraries.Show less
-
-
Jun 17, 2026
Jan 30, 2025
8.5 HIGH· v4
N/A· v3
N/A· v2
A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with l...Show more
A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and load a specially crafted openssl.conf file leading to the execution of a malicious DLL (Dynamic-Link Library) with elevated privileges.Show less
-
-
Jun 17, 2026
Jan 24, 2025
N/A· v4
8.6 HIGH· v3
N/A· v2
DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress Win 98SE Dev Kit installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.
-
-
Jun 17, 2026
Jan 24, 2025
N/A· v4
8.6 HIGH· v3
N/A· v2
DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress SDK installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.
-
-
Jun 17, 2026
Jan 24, 2025
N/A· v4
8.6 HIGH· v3
N/A· v2
DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress 4 SDK installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.
-
-
Jun 17, 2026
Jan 24, 2025
N/A· v4
8.6 HIGH· v3
N/A· v2
DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress Dev Kit installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.
-
-
Jun 17, 2026
Jan 24, 2025
N/A· v4
8.6 HIGH· v3
N/A· v2
DLL hijacking vulnerabilities, caused by an uncontrolled search path in the CP210x VCP Windows installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.
-
-
Jun 17, 2026
Jan 24, 2025
N/A· v4
8.6 HIGH· v3
N/A· v2
DLL hijacking vulnerabilities, caused by an uncontrolled search path in the  CP210 VCP Win 2k installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.