← Back
CWE-427

1,189 CVEs • Abstraction: Base

Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

JSON object

Loading...

CVEs (1,189)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nvidia
1Gpu Display Driver
Jun 17, 2026
Jul 22, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
NVIDIA GPU Display Driver for Windows contains a vulnerability in nvidia-smi where an uncontrolled DLL loading path may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.
1Lenovo
1Pcmanager
Jun 17, 2026
Jul 16, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.500.5102, that could allow privilege escalation.
1Bat Project
1Bat
Jun 17, 2026
Jul 15, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
sharkdp BAT before 0.18.2 executes less.exe from the current working directory.
1Zscaler
1Client Connector
Jun 17, 2026
Jul 15, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
The Zscaler Client Connector for Windows prior to 2.1.2.105 had a DLL hijacking vulnerability caused due to the configuration of OpenSSL. A local adversary may be able to execute arbitrary code in the SYSTEM context.
1Paloaltonetworks
1Cortex Xdr Agent
Jun 17, 2026
Jul 15, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated local Windows user to execute programs with SYSTEM privileges. Exploiti...Show more
A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated local Windows user to execute programs with SYSTEM privileges. Exploiting this vulnerability requires the user to have file creation privilege in the Windows root directory (such as C:\). This issue impacts: All versions of Cortex XDR agent 6.1 without content update 181 or a later version; All versions of Cortex XDR agent 7.2 without content update 181 or a later version; All versions of Cortex XDR agent 7.3 without content update 181 or a later version. Cortex XDR agent 5.0 versions are not impacted by this issue. Content updates are required to resolve this issue and are automatically applied for the agent.Show less
1Raonwiz
1Raon K Editor
Jun 17, 2026
Jul 14, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
An issue in RAONWIZ K Editor v2018.0.0.10 allows attackers to perform a DLL hijacking attack when the service or system is restarted.
1Vmware
1Thinapp
Jun 17, 2026
Jul 13, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
VMware Thinapp version 5.x prior to 5.2.10 contain a DLL hijacking vulnerability due to insecure loading of DLLs. A malicious actor with non-administrative privileges may exploit this vulnerability to elevate privileges...Show more
VMware Thinapp version 5.x prior to 5.2.10 contain a DLL hijacking vulnerability due to insecure loading of DLLs. A malicious actor with non-administrative privileges may exploit this vulnerability to elevate privileges to administrator level on the Windows operating system having VMware ThinApp installed on it.Show less
1Stormshield
1Endpoint Security
Jun 17, 2026
Jul 13, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Stormshield Endpoint Security Evolution 2.0.0 through 2.0.2 does not accomplish the intended defense against local administrators who can replace the Visual C++ runtime DLLs (in %WINDIR%\system32) with malicious ones.
1Delta Project
1Delta
Jun 17, 2026
Jul 13, 2021
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
dandavison delta before 0.8.3 on Windows resolves an executable's pathname as a relative path from the current directory.
1Openvpn
1Connect
Jun 17, 2026
Jul 2, 2021
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level...Show more
OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (OpenVPNConnect.exe).Show less
1Openvpn
1Openvpn
Jun 17, 2026
Jul 2, 2021
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege le...Show more
OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (openvpn.exe).Show less
1Adobe
1After Effects
Jun 17, 2026
Jun 28, 2021
N/A· v4
8.6 HIGH· v3
9.3 HIGH· v2
Adobe After Effects version 18.1 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An unauthenticated attacker could exploit this to to plant custom binaries and execute them with System per...Show more
Adobe After Effects version 18.1 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An unauthenticated attacker could exploit this to to plant custom binaries and execute them with System permissions. Exploitation of this issue requires user interaction.Show less
1Mozilla
1Thunderbird
Jun 17, 2026
Jun 24, 2021
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filename that isn't distributed by Thunderbird. If a computer has already been infected...Show more
When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filename that isn't distributed by Thunderbird. If a computer has already been infected with a malicious library of the alternative filename, and the malicious library has been copied to a directory that is contained in the search path for executable libraries, then Thunderbird will load the incorrect library. This vulnerability affects Thunderbird < 78.9.1.Show less
1Vmware
3App Volumes
Remote ConsoleTools
Jun 17, 2026
Jun 23, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App Volumes (2.x prior to 2.18.10 and 4 prior to 2103) contain a local privilege escalation vulnerabili...Show more
VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App Volumes (2.x prior to 2.18.10 and 4 prior to 2103) contain a local privilege escalation vulnerability. An attacker with normal access to a virtual machine may exploit this issue by placing a malicious file renamed as `openssl.cnf' in an unrestricted directory which would allow code to be executed with elevated privileges.Show less
1Cisco
1Anyconnect Secure Mobility Client
Jun 17, 2026
Jun 16, 2021
N/A· v4
6.7 MEDIUM· v3
6.2 MEDIUM· v2
A vulnerability in the DLL loading mechanism of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture...Show more
A vulnerability in the DLL loading mechanism of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. This vulnerability is due to a race condition in the signature verification process for DLL files that are loaded on an affected device. An attacker could exploit this vulnerability by sending a series of crafted interprocess communication (IPC) messages to the AnyConnect process. A successful exploit could allow the attacker to execute arbitrary code on the affected device with SYSTEM privileges. To exploit this vulnerability, the attacker must have valid credentials on the Windows system.Show less
1Teamviewer
1Teamviewer
Jun 17, 2026
Jun 16, 2021
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations.
1Mcafee
1Mcafee Agent
Jun 17, 2026
Jun 10, 2021
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
A vulnerability in the preloading mechanism of specific dynamic link libraries in McAfee Agent for Windows prior to 5.7.3 could allow an authenticated, local attacker to perform a DLL preloading attack with unsigned DLLs...Show more
A vulnerability in the preloading mechanism of specific dynamic link libraries in McAfee Agent for Windows prior to 5.7.3 could allow an authenticated, local attacker to perform a DLL preloading attack with unsigned DLLs. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. This would result in the user gaining elevated permissions and being able to execute arbitrary code.Show less
1F5
1Big Ip Access Policy Manager
Jun 17, 2026
Jun 10, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, a DLL hijacking issue exists in cachecleaner.dll included in the BIG-IP Edge Client Windows Installer. Note: Software versions which have reached End o...Show more
On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, a DLL hijacking issue exists in cachecleaner.dll included in the BIG-IP Edge Client Windows Installer. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.Show less
1Paloaltonetworks
1Cortex Xdr Agent
Jun 17, 2026
Jun 10, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A local privilege escalation vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated local Windows user to execute programs with SYSTEM privileges. This requires...Show more
A local privilege escalation vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated local Windows user to execute programs with SYSTEM privileges. This requires the user to have the privilege to create files in the Windows root directory or to manipulate key registry values. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.11; Cortex XDR agent 6.1 versions earlier than Cortex XDR agent 6.1.8; Cortex XDR agent 7.2 versions earlier than Cortex XDR agent 7.2.3; All versions of Cortex XDR agent 7.2 without content update release 171 or a later version.Show less
1Intel
1Unite
Jun 17, 2026
Jun 9, 2021
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
Uncontrolled search path in the Intel Unite(R) Client for Windows before version 4.2.25031 may allow an authenticated user to potentially enable an escalation of privilege via local access.