← Back
CWE-427

1,189 CVEs • Abstraction: Base

Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

JSON object

Loading...

CVEs (1,189)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vmware
1Tools
Jun 17, 2026
Mar 3, 2022
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
VMware Tools for Windows (11.x.y and 10.x.y prior to 12.0.0) contains an uncontrolled search path vulnerability. A malicious actor with local administrative privileges in the Windows guest OS, where VMware Tools is insta...Show more
VMware Tools for Windows (11.x.y and 10.x.y prior to 12.0.0) contains an uncontrolled search path vulnerability. A malicious actor with local administrative privileges in the Windows guest OS, where VMware Tools is installed, may be able to execute code with system privileges in the Windows guest OS due to an uncontrolled search path element.Show less
1Adobe
1Creative Cloud Desktop Application
Jun 17, 2026
Feb 16, 2022
N/A· v4
7.0 HIGH· v3
5.1 MEDIUM· v2
Adobe Creative Cloud Desktop version 2.7.0.13 (and earlier) is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation...Show more
Adobe Creative Cloud Desktop version 2.7.0.13 (and earlier) is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must download a malicious DLL file. The attacker has to deliver the DLL on the same folder as the installer which makes it as a high complexity attack vector.Show less
1Atlassian
2Confluence Data Center
Confluence Server
Jun 17, 2026
Feb 15, 2022
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer. This...Show more
Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer. This vulnerability only affects installations of Confluence Server and Data Center on Windows. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.Show less
1Axis
1Ip Utility
Jun 17, 2026
Feb 14, 2022
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
AXIS IP Utility before 4.18.0 allows for remote code execution and local privilege escalation by the means of DLL hijacking. IPUtility.exe would attempt to load DLLs from its current working directory which could allow f...Show more
AXIS IP Utility before 4.18.0 allows for remote code execution and local privilege escalation by the means of DLL hijacking. IPUtility.exe would attempt to load DLLs from its current working directory which could allow for remote code execution if a compromised DLL would be placed in the same folder.Show less
1Kde
2Kate
Ktexteditor
Jun 17, 2026
Feb 11, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The LSP (Language Server Protocol) plugin in KDE Kate before 21.12.2 and KTextEditor before 5.91.0 tries to execute the associated LSP server binary when opening a file of a given type. If this binary is absent from the...Show more
The LSP (Language Server Protocol) plugin in KDE Kate before 21.12.2 and KTextEditor before 5.91.0 tries to execute the associated LSP server binary when opening a file of a given type. If this binary is absent from the PATH, it will try running the LSP server binary in the directory of the file that was just opened (due to a misunderstanding of the QProcess API, that was never intended). This can be an untrusted directory.Show less
1Acronis
1Vss Doctor
Jun 17, 2026
Feb 11, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53
1Foxit
2Pdf Editor
Pdf Reader
Jun 17, 2026
Feb 11, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files.
1Sap
1Adaptive Server Enterprise
Jun 17, 2026
Feb 9, 2022
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
SAP Adaptive Server Enterprise (ASE) - version 16.0, installation makes an entry in the system PATH environment variable in Windows platform which, under certain conditions, allows a Standard User to execute malicious Wi...Show more
SAP Adaptive Server Enterprise (ASE) - version 16.0, installation makes an entry in the system PATH environment variable in Windows platform which, under certain conditions, allows a Standard User to execute malicious Windows binaries which may lead to privilege escalation on the local system. The issue is with the ASE installer and does not impact other ASE binaries.Show less
1Intel
1Graphics Performance Analyzers
Jun 17, 2026
Feb 9, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Uncontrolled search path in the Intel(R) GPA software before version 21.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
22Amt Ac 8260 Firmware
Amt Ac 8265 FirmwareAmt Ac 9260 Firmware+19 more
Jun 17, 2026
Feb 9, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Uncontrolled Search Path Element in software for Intel(R) PROSet/Wireless Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable escalation of privilege via local access.
1Acronis
2Cyber Protect Home Office
True Image
Jun 17, 2026
Feb 4, 2022
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
Local privilege escalation due to DLL hijacking vulnerability in Acronis Media Builder service. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39612, Acronis True Image 2021...Show more
Local privilege escalation due to DLL hijacking vulnerability in Acronis Media Builder service. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39612, Acronis True Image 2021 (Windows) before build 39287Show less
1Acronis
2Cyber Protect Home Office
True Image
Jun 17, 2026
Feb 4, 2022
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39612, Acronis True Image 2021 (Windows) before build 39287
1Amd
2Radeon Pro Software
Radeon Software
Jun 17, 2026
Feb 4, 2022
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop its malicious DLL file in any location which is in path environment variable.
1Emerson
1Deltav
Jun 17, 2026
Jan 28, 2022
N/A· v4
7.3 HIGH· v3
6.9 MEDIUM· v2
Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Distributed Control System Controllers and Workstations (All versions) when some DeltaV services are st...Show more
Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Distributed Control System Controllers and Workstations (All versions) when some DeltaV services are started.Show less
1Mcafee
1Agent
Jun 17, 2026
Jan 19, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5. McAfee Agent uses openssl.cnf during the build process to specify the OPENSSLDIR variable as a subdirectory within the installation directory. A lo...Show more
A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5. McAfee Agent uses openssl.cnf during the build process to specify the OPENSSLDIR variable as a subdirectory within the installation directory. A low privilege user could have created subdirectories and executed arbitrary code with SYSTEM privileges by creating the appropriate pathway to the specifically created malicious openssl.cnf file.Show less
1Paloaltonetworks
1Cortex Xdr Agent
Jun 17, 2026
Jan 12, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authenticated local user to execute programs with elevated privileges. This issue impacts: Cortex XDR agen...Show more
A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authenticated local user to execute programs with elevated privileges. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12; Cortex XDR agent 6.1 versions earlier than Cortex XDR agent 6.1.9.Show less
1Mcafee
1Techcheck
Jun 17, 2026
Jan 11, 2022
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
Uncontrolled search path element vulnerability in McAfee TechCheck prior to 4.0.0.2 allows a local administrator to load their own Dynamic Link Library (DLL) gaining elevation of privileges to system user. This was achie...Show more
Uncontrolled search path element vulnerability in McAfee TechCheck prior to 4.0.0.2 allows a local administrator to load their own Dynamic Link Library (DLL) gaining elevation of privileges to system user. This was achieved through placing the malicious DLL in the same directory that the process was run from.Show less
2Fedoraproject
Pypa
2Fedora
Pipenv
Jun 17, 2026
Jan 10, 2022
N/A· v4
8.6 HIGH· v3
9.3 HIGH· v2
pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requirements files allows an attacker to insert a specially crafted string inside...Show more
pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requirements files allows an attacker to insert a specially crafted string inside a comment anywhere within a requirements.txt file, which will cause victims who use pipenv to install the requirements file to download dependencies from a package index server controlled by the attacker. By embedding malicious code in packages served from their malicious index server, the attacker can trigger arbitrary remote code execution (RCE) on the victims' systems. If an attacker is able to hide a malicious `--index-url` option in a requirements file that a victim installs with pipenv, the attacker can embed arbitrary malicious code in packages served from their malicious index server that will be executed on the victim's host during installation (remote code execution/RCE). When pip installs from a source distribution, any code in the setup.py is executed by the install process. This issue is patched in version 2022.1.8. The GitHub Security Advisory contains more information about this vulnerability.Show less
1Checkpoint
1Endpoint Security
Jun 17, 2026
Jan 10, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Users have access to the directory where the installation repair occurs. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted EXE i...Show more
Users have access to the directory where the installation repair occurs. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted EXE in the repair folder which runs with the Check Point Remote Access Client privileges.Show less
1Rapid7
1Insight Agent
Jun 17, 2026
Dec 14, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Rapid7 Insight Agent, versions 3.0.1 to 3.1.2.34, suffer from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when Insight Agent versions 3.0.1 to 3.1.2.34 start, the Python interpreter...Show more
Rapid7 Insight Agent, versions 3.0.1 to 3.1.2.34, suffer from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when Insight Agent versions 3.0.1 to 3.1.2.34 start, the Python interpreter attempts to load python3.dll at "C:\DLLs\python3.dll," which normally is writable by locally authenticated users. Because of this, a malicious local user could use Insight Agent's startup conditions to elevate to SYSTEM privileges. This issue was fixed in Rapid7 Insight Agent 3.1.2.35. This vulnerability is a regression of CVE-2019-5629.Show less