← Back
CWE-427

1,189 CVEs • Abstraction: Base

Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

JSON object

Loading...

CVEs (1,189)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Safervpn
1Safervpn
Jun 17, 2026
Jan 12, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
SaferVPN for Windows Ver 5.0.3.3 through 5.0.4.15 could allow local privilege escalation from low privileged users to SYSTEM via a crafted openssl configuration file. This issue is similar to CVE-2019-12572.
1Anydesk
1Anydesk
Jun 17, 2026
Jan 11, 2021
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
AnyDesk before 6.1.0 on Windows, when run in portable mode on a system where the attacker has write access to the application directory, allows this attacker to compromise a local user account via a read-only setting for...Show more
AnyDesk before 6.1.0 on Windows, when run in portable mode on a system where the attacker has write access to the application directory, allows this attacker to compromise a local user account via a read-only setting for a Trojan horse gcapi.dll file.Show less
1Epson
2Epsonnet Setupmanager
Offirio Synergyware Printdirector
Jun 17, 2026
Dec 24, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Untrusted search path vulnerability in self-extracting files created by EpsonNet SetupManager versions 2.2.14 and earlier, and Offirio SynergyWare PrintDirector versions 1.6x/1.6y and earlier allows an attacker to gain p...Show more
Untrusted search path vulnerability in self-extracting files created by EpsonNet SetupManager versions 2.2.14 and earlier, and Offirio SynergyWare PrintDirector versions 1.6x/1.6y and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.Show less
1Dlink
1Dsl2888a Firmware
Jun 17, 2026
Dec 22, 2020
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It has a misconfigured FTP service that allows a malicious network user to access system folders and download sensitive file...Show more
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It has a misconfigured FTP service that allows a malicious network user to access system folders and download sensitive files (such as the password hash file).Show less
1Westerndigital
1Dashboard
Jun 17, 2026
Dec 12, 2020
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
Western Digital Dashboard before 3.2.2.9 allows DLL Hijacking that leads to compromise of the SYSTEM account.
1Adobe
1Lightroom
Jun 17, 2026
Dec 11, 2020
N/A· v4
7.0 HIGH· v3
3.7 LOW· v2
Adobe Lightroom Classic version 10.0 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of th...Show more
Adobe Lightroom Classic version 10.0 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Show less
1Adobe
1Prelude
Jun 17, 2026
Dec 11, 2020
N/A· v4
7.0 HIGH· v3
3.7 LOW· v2
Adobe Prelude version 9.0.1 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user inte...Show more
Adobe Prelude version 9.0.1 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Show less
1Paloaltonetworks
1Cortex Xdr Agent
Jun 17, 2026
Dec 9, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that allows an authenticated local Windows user to execute programs with SYSTEM privileges. This requires t...Show more
A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that allows an authenticated local Windows user to execute programs with SYSTEM privileges. This requires the user to have the privilege to create files in the Windows root directory. This issue impacts: All versions of Cortex XDR Agent 7.1 with content update 149 and earlier versions; All versions of Cortex XDR Agent 7.2 with content update 149 and earlier versions.Show less
1Kaspersky
1Anti Ransomware Tool
Jun 17, 2026
Dec 4, 2020
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
The installer of Kaspersky Anti-Ransomware Tool (KART) prior to KART 4.0 Patch C was vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges during installation process.
1Canonical
2Snapcraft
Ubuntu Linux
Jun 17, 2026
Dec 4, 2020
N/A· v4
6.8 MEDIUM· v3
4.4 MEDIUM· v2
In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a malicious snap to gain code execution within the context of another snap if both plug the home interface...Show more
In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a malicious snap to gain code execution within the context of another snap if both plug the home interface or similar. This issue affects snapcraft versions prior to 4.4.4, prior to 2.43.1+16.04.1, and prior to 2.43.1+18.04.1.Show less
1Checkpoint
1Endpoint Security
Jun 17, 2026
Dec 3, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes place. Since the MS Installer allows regular users to run the repair, a...Show more
Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes place. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted DLL in the repair folder which will run with the Endpoint client’s privileges.Show less
1Cyberark
1Endpoint Privilege Manager
Jun 17, 2026
Nov 27, 2020
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
CyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism by injecting a DLL into a process that normally has credential access, such as a Chrome process that...Show more
CyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism by injecting a DLL into a process that normally has credential access, such as a Chrome process that reads credentials from a SQLite database.Show less
1Epson
33Album Print
Color Calibration UtilityColorbase+30 more
Jun 17, 2026
Nov 24, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
1Intel
1Vtune Profiler
Jun 17, 2026
Nov 12, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Uncontrolled search path in the Intel(R) VTune(TM) Profiler before version 2020 Update 1 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Scs Add On For Microsoft Sccm
Jun 17, 2026
Nov 12, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Uncontrolled search path in Intel(R) SCS Add-on for Microsoft* SCCM before version 2.1.10 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Nov 12, 2020
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
Various components in Ivanti Endpoint Manager through 2020.1.1 rely on Windows search order when loading a (nonexistent) library file, allowing (under certain conditions) one to gain code execution (and elevation of priv...Show more
Various components in Ivanti Endpoint Manager through 2020.1.1 rely on Windows search order when loading a (nonexistent) library file, allowing (under certain conditions) one to gain code execution (and elevation of privileges to the level of privilege held by the vulnerable component such as NT AUTHORITY\SYSTEM) via DLL hijacking. This affects ldiscn32.exe, IpmiRedirectionService.exe, LDAPWhoAmI.exe, and ldprofile.exe.Show less
1Nvidia
1Geforce Now
Jun 17, 2026
Nov 11, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
NVIDIA GeForce NOW application software on Windows, all versions prior to 2.0.25.119, contains a vulnerability in its open-source software dependency in which the OpenSSL library is vulnerable to binary planting attacks...Show more
NVIDIA GeForce NOW application software on Windows, all versions prior to 2.0.25.119, contains a vulnerability in its open-source software dependency in which the OpenSSL library is vulnerable to binary planting attacks by a local user, which may lead to code execution or escalation of privileges.Show less
1Bbraun
1Onlinesuite Application Package
Jun 17, 2026
Nov 6, 2020
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
A DLL hijacking vulnerability in the B. Braun OnlineSuite Version AP 3.0 and earlier allows local attackers to execute code on the system as a high privileged user.
1Git Large File Storage Project
1Git Large File Storage
Jun 17, 2026
Nov 5, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Git LFS 2.12.0 allows Remote Code Execution.
1Ea
1Origin
Jun 17, 2026
Nov 2, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability exists in the Origin Client that could allow a non-Administrative user to elevate their access to either Administrator or System. Once the user has obtained elevated access, they may be able to take contr...Show more
A vulnerability exists in the Origin Client that could allow a non-Administrative user to elevate their access to either Administrator or System. Once the user has obtained elevated access, they may be able to take control of the system and perform actions otherwise reserved for high privileged users or system Administrators.Show less