CWE-427
1,189 CVEs • Abstraction: Base
Uncontrolled Search Path Element
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
CVEs (1,189)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
VMware Tools for Windows (11.x.y and 10.x.y prior to 12.0.0) contains an uncontrolled search path vulnerability. A malicious actor with local administrative privileges in the Windows guest OS, where VMware Tools is insta...Show more |
1Adobe 1Creative Cloud Desktop Application Jun 17, 2026 Feb 16, 2022 N/A· v4 7.0 HIGH· v3 5.1 MEDIUM· v2 Adobe Creative Cloud Desktop version 2.7.0.13 (and earlier) is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation...Show more |
1Atlassian 2Confluence Data Center Confluence ServerJun 17, 2026 Feb 15, 2022 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer. This...Show more |
AXIS IP Utility before 4.18.0 allows for remote code execution and local privilege escalation by the means of DLL hijacking. IPUtility.exe would attempt to load DLLs from its current working directory which could allow f...Show more |
The LSP (Language Server Protocol) plugin in KDE Kate before 21.12.2 and KTextEditor before 5.91.0 tries to execute the associated LSP server binary when opening a file of a given type. If this binary is absent from the...Show more |
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53 |
1Foxit 2Pdf Editor Pdf ReaderJun 17, 2026 Feb 11, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files. |
1Sap 1Adaptive Server Enterprise Jun 17, 2026 Feb 9, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 SAP Adaptive Server Enterprise (ASE) - version 16.0, installation makes an entry in the system PATH environment variable in Windows platform which, under certain conditions, allows a Standard User to execute malicious Wi...Show more |
1Intel 1Graphics Performance Analyzers Jun 17, 2026 Feb 9, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Uncontrolled search path in the Intel(R) GPA software before version 21.2 may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Intel 22Amt Ac 8260 Firmware Amt Ac 8265 FirmwareAmt Ac 9260 Firmware+19 moreJun 17, 2026 Feb 9, 2022 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Uncontrolled Search Path Element in software for Intel(R) PROSet/Wireless Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable escalation of privilege via local access. |
1Acronis 2Cyber Protect Home Office True ImageJun 17, 2026 Feb 4, 2022 N/A· v4 7.3 HIGH· v3 4.4 MEDIUM· v2 Local privilege escalation due to DLL hijacking vulnerability in Acronis Media Builder service. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39612, Acronis True Image 2021...Show more |
1Acronis 2Cyber Protect Home Office True ImageJun 17, 2026 Feb 4, 2022 N/A· v4 7.3 HIGH· v3 4.4 MEDIUM· v2 Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39612, Acronis True Image 2021 (Windows) before build 39287 |
1Amd 2Radeon Pro Software Radeon SoftwareJun 17, 2026 Feb 4, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop its malicious DLL file in any location which is in path environment variable. |
Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Distributed Control System Controllers and Workstations (All versions) when some DeltaV services are st...Show more |
A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5. McAfee Agent uses openssl.cnf during the build process to specify the OPENSSLDIR variable as a subdirectory within the installation directory. A lo...Show more |
1Paloaltonetworks 1Cortex Xdr Agent Jun 17, 2026 Jan 12, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authenticated local user to execute programs with elevated privileges. This issue impacts: Cortex XDR agen...Show more |
Uncontrolled search path element vulnerability in McAfee TechCheck prior to 4.0.0.2 allows a local administrator to load their own Dynamic Link Library (DLL) gaining elevation of privileges to system user. This was achie...Show more |
2Fedoraproject Pypa2Fedora PipenvJun 17, 2026 Jan 10, 2022 N/A· v4 8.6 HIGH· v3 9.3 HIGH· v2 pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requirements files allows an attacker to insert a specially crafted string inside...Show more |
Users have access to the directory where the installation repair occurs. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted EXE i...Show more |
Rapid7 Insight Agent, versions 3.0.1 to 3.1.2.34, suffer from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when Insight Agent versions 3.0.1 to 3.1.2.34 start, the Python interpreter...Show more |