← Back
CWE-427

1,189 CVEs • Abstraction: Base

Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

JSON object

Loading...

CVEs (1,189)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sonicwall
1Global Vpn Client
Jun 17, 2026
Dec 8, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
SonicWall Global VPN client version 4.10.6 (32-bit and 64-bit) and earlier have a DLL Search Order Hijacking vulnerability. Successful exploitation via a local attacker could result in remote code execution in the target...Show more
SonicWall Global VPN client version 4.10.6 (32-bit and 64-bit) and earlier have a DLL Search Order Hijacking vulnerability. Successful exploitation via a local attacker could result in remote code execution in the target system.Show less
1Kaseya
1Unitrends Backup
Jun 17, 2026
Dec 6, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Unitrends Windows agent was vulnerable to DLL injection and binary planting due to insecure default permissions. This allowed privilege esca...Show more
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Unitrends Windows agent was vulnerable to DLL injection and binary planting due to insecure default permissions. This allowed privilege escalation from an unprivileged user to SYSTEM.Show less
1Fortinet
2Forticlient
Forticlient Enterprise Management Server
Jun 17, 2026
Dec 1, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
An unsafe search path vulnerability in FortiClientWindows 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x and FortiClientEMS 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x may allow an attacker to perform a DLL Hijack attack on affected devi...Show more
An unsafe search path vulnerability in FortiClientWindows 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x and FortiClientEMS 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x may allow an attacker to perform a DLL Hijack attack on affected devices via a malicious OpenSSL engine library in the search path.Show less
1Acronis
3Agent
Cyber ProtectCyber Protect Home Office
Jun 17, 2026
Nov 29, 2021
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
DLL hijacking could lead to denial of service. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27305, Acronis Cyber Protect Home Office (Wi...Show more
DLL hijacking could lead to denial of service. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27305, Acronis Cyber Protect Home Office (Windows) before build 39612Show less
1Acronis
1Cyber Protect
Jun 17, 2026
Nov 29, 2021
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
DLL hijacking could lead to local privilege escalation. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035
1Intel
157265 Firmware
Ac1550 FirmwareAc 3165 Firmware+12 more
Jun 17, 2026
Nov 17, 2021
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Uncontrolled search path in software installer for Intel(R) PROSet/Wireless WiFi in Windows 10 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Lenovo
1Antilles
Jun 17, 2026
Nov 12, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A dependency confusion vulnerability was reported in the Antilles open-source software prior to version 1.0.1 that could allow for remote code execution during installation due to a package listed in requirements.txt not...Show more
A dependency confusion vulnerability was reported in the Antilles open-source software prior to version 1.0.1 that could allow for remote code execution during installation due to a package listed in requirements.txt not existing in the public package index (PyPi). MITRE classifies this weakness as an Uncontrolled Search Path Element (CWE-427) in which a private package dependency may be replaced by an unauthorized package of the same name published to a well-known public repository such as PyPi. The configuration has been updated to only install components built by Antilles, removing all other public package indexes. Additionally, the antilles-tools dependency has been published to PyPi.Show less
1Mcafee
1Drive Encryption
Jun 17, 2026
Nov 10, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
DLL Search Order Hijacking Vulnerability in McAfee Drive Encryption (MDE) prior to 7.3.0 HF2 (7.3.0.183) allows local users to execute arbitrary code and escalate privileges via execution from a compromised folder.
1Deltaww
1Dialink
Jun 17, 2026
Nov 3, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow an attacker to modify the installation directory and upload malicious f...Show more
Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow an attacker to modify the installation directory and upload malicious files.Show less
1Deltaww
1Dialink
Jun 17, 2026
Nov 3, 2021
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Delta Electronics DIALink versions 1.2.4.0 and prior insecurely loads libraries, which may allow an attacker to use DLL hijacking and takeover the system where the software is installed.
1Vmware
1Installbuilder
Jun 17, 2026
Oct 29, 2021
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Under certain circumstances, when manipulating the Windows registry, InstallBuilder uses the reg.exe system command. The full path to the command is not enforced, which results in a search in the search path until a bina...Show more
Under certain circumstances, when manipulating the Windows registry, InstallBuilder uses the reg.exe system command. The full path to the command is not enforced, which results in a search in the search path until a binary can be identified. This makes the installer/uninstaller vulnerable to Path Interception by Search Order Hijacking, potentially allowing an attacker to plant a malicious reg.exe command so it takes precedence over the system command. The vulnerability only affects Windows installers.Show less
1Checkpoint
2Harmony Browse
Sandblast Agent For Browsers
Jun 17, 2026
Oct 22, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The Harmony Browse and the SandBlast Agent for Browsers installers must have admin privileges to execute some steps during the installation. Because the MS Installer allows regular users to repair their installation, an...Show more
The Harmony Browse and the SandBlast Agent for Browsers installers must have admin privileges to execute some steps during the installation. Because the MS Installer allows regular users to repair their installation, an attacker running an installer before 90.08.7405 can start the installation repair and place a specially crafted binary in the repair folder, which runs with the admin privileges.Show less
1Auvesy
1Versiondog
Jun 17, 2026
Oct 22, 2021
N/A· v4
7.1 HIGH· v3
4.3 MEDIUM· v2
Many of the services used by the affected product do not specify full paths for the DLLs they are loading. An attacker can exploit the uncontrolled search path by implanting their own DLL near the affected product’s bina...Show more
Many of the services used by the affected product do not specify full paths for the DLLs they are loading. An attacker can exploit the uncontrolled search path by implanting their own DLL near the affected product’s binaries, thus hijacking the loaded DLL.Show less
1Trendmicro
1Apex One
Jun 17, 2026
Oct 21, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the abili...Show more
An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar but not identical to CVE-2021-42101.Show less
1Trendmicro
1Apex One
Jun 17, 2026
Oct 21, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service agents could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain th...Show more
An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service agents could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.Show less
1Trendmicro
1Apex One
Jun 17, 2026
Oct 21, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the abili...Show more
An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar but not identical to CVE-2021-42103.Show less
1Adobe
2Acrobat Dc
Acrobat Reader Dc
Jun 17, 2026
Sep 29, 2021
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Uncontrolled Search Path Element vulnerability. A local attacker with non-administ...Show more
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Uncontrolled Search Path Element vulnerability. A local attacker with non-administrative privileges can plant a malicious DLL to achieve arbitrary code execution in the context of the current user via DLL hijacking. Exploitation of this issue requires user interaction.Show less
1Trendmicro
1Housecall For Home Networks
Jun 17, 2026
Sep 29, 2021
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
An uncontrolled search path element privilege escalation vulnerability in Trend Micro HouseCall for Home Networks version 5.3.1225 and below could allow an attacker to escalate privileges by placing a custom crafted file...Show more
An uncontrolled search path element privilege escalation vulnerability in Trend Micro HouseCall for Home Networks version 5.3.1225 and below could allow an attacker to escalate privileges by placing a custom crafted file in a specific directory to load a malicious library. Please note that an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.Show less
1Asus
1Armoury Crate Lite Service
Jun 17, 2026
Sep 27, 2021
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
ASUS ROG Armoury Crate Lite before 4.2.10 allows local users to gain privileges by placing a Trojan horse file in the publicly writable %PROGRAMDATA%\ASUS\GamingCenterLib directory.
1Dr.web
1Security Space
Jun 17, 2026
Sep 24, 2021
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Dr.Web Firewall 12.5.2.4160 on Windows incorrectly restricts applications signed by Dr.Web. A DLL for a custom payload within a legitimate binary (e.g., frwl_svc.exe) bypasses firewall filters.