← Back
CWE-427

1,189 CVEs • Abstraction: Base

Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

JSON object

Loading...

CVEs (1,189)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tencent
1Tencent
Jun 17, 2026
Sep 3, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
The Shenzhen Tencent app 5.8.2.5300 for PC platforms (from Tencent App Center) has a DLL hijacking vulnerability. Attackers can use this vulnerability to execute malicious code.
1163
1Netease Mail Master
Jun 17, 2026
Sep 3, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Guangzhou NetEase Mail Master 4.14.1.1004 on Windows has a DLL hijacking vulnerability. Attackers can use this vulnerability to execute malicious code.
1Tencent
1Tim
Jun 17, 2026
Sep 3, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Shenzhen Tencent TIM Windows client 3.0.0.21315 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious code.
1163
1Netease Youdao Dictionary
Jun 17, 2026
Sep 3, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
NetEase Youdao Dictionary has a DLL hijacking vulnerability, which can be exploited by attackers to gain server permissions. This affects Guangzhou NetEase Youdao Dictionary 8.9.2.0.
1360
1Speed Browser
Jun 17, 2026
Sep 3, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
360 Speed Browser 12.0.1247.0 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious code. It is a dual-core browser owned by Beijing Qihoo Technology.
1Kaspersky
2Security Center
Security Center Web Console
Jun 17, 2026
Sep 2, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Installers of Kaspersky Security Center and Kaspersky Security Center Web Console prior to 12 & prior to 12 Patch A were vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges in the system.
1Johnkerl
1Miller
Jun 17, 2026
Sep 2, 2020
N/A· v4
8.6 HIGH· v3
4.4 MEDIUM· v2
In Miller (command line utility) using the configuration file support introduced in version 5.9.0, it is possible for an attacker to cause Miller to run arbitrary code by placing a malicious `.mlrrc` file in the working...Show more
In Miller (command line utility) using the configuration file support introduced in version 5.9.0, it is possible for an attacker to cause Miller to run arbitrary code by placing a malicious `.mlrrc` file in the working directory. See linked GitHub Security Advisory for complete details. A fix is ready and will be released as Miller 5.9.1.Show less
2Broadcom
Pivotal Software
2Rabbitmq
Rabbitmq Server
Jun 17, 2026
Aug 31, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation direc...Show more
RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation directory and local access on Windows could carry out a local binary hijacking (planting) attack and execute arbitrary code.Show less
2Opensuse
Postgresql
2Leap
Postgresql
Jun 17, 2026
Aug 24, 2020
N/A· v4
7.1 HIGH· v3
4.6 MEDIUM· v2
It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to...Show more
It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.Show less
1Adobe
1Lightroom
Jun 17, 2026
Aug 19, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Adobe Lightroom versions 9.2.0.10 and earlier have an insecure library loading vulnerability. Successful exploitation could lead to privilege escalation.
1Cisco
1Anyconnect Secure Mobility Client
Jun 17, 2026
Aug 17, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulne...Show more
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due to insufficient validation of resources that are loaded by the application at run time. An attacker could exploit this vulnerability by sending a crafted IPC message to the AnyConnect process. A successful exploit could allow the attacker to execute arbitrary code on the affected machine with SYSTEM privileges. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system.Show less
1Zoom
1Sharing Service
Jun 17, 2026
Aug 14, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability related to Dynamic-link Library (“DLL”) loading in the Zoom Sharing Service would allow an attacker who had local access to a machine on which the service was running with elevated privileges to elevate t...Show more
A vulnerability related to Dynamic-link Library (“DLL”) loading in the Zoom Sharing Service would allow an attacker who had local access to a machine on which the service was running with elevated privileges to elevate their system privileges as well through use of a malicious DLL. Zoom addressed this issue, which only applies to Windows users, in the 5.0.4 client release.Show less
1Philips
1Smartcontrol
Jun 17, 2026
Aug 13, 2020
N/A· v4
7.3 HIGH· v3
6.9 MEDIUM· v2
An Uncontrolled Search Path Element (CWE-427) vulnerability in SmartControl version 4.3.15 and versions released before April 15, 2020 may allow an authenticated user to escalate privileges by placing a specially crafted...Show more
An Uncontrolled Search Path Element (CWE-427) vulnerability in SmartControl version 4.3.15 and versions released before April 15, 2020 may allow an authenticated user to escalate privileges by placing a specially crafted DLL file in the search path. This issue was fixed in version 1.0.7, which was released after April 15, 2020. (Note, the version numbering system changed significantly between version 4.3.15 and version 1.0.7.)Show less
1Intel
1Rste Software Raid
Jun 17, 2026
Aug 13, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Uncontrolled search path in the installer for Intel(R) RSTe Software RAID Driver for the Intel(R) Server Board M10JNP2SB before version 4.7.0.1119 may allow an authenticated user to potentially enable escalation of privi...Show more
Uncontrolled search path in the installer for Intel(R) RSTe Software RAID Driver for the Intel(R) Server Board M10JNP2SB before version 4.7.0.1119 may allow an authenticated user to potentially enable escalation of privilege via local access.Show less
1Hp
14Elite X2 1012 G1 Firmware
Elite X2 1012 G2 FirmwareElitebook 1030 G1 Firmware+11 more
Jun 17, 2026
Aug 12, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on various Dell, HP, and Lenovo laptops, allows attackers to conduct Path Disclosure attacks via a "fake" DLL file.
1Teradici
2Graphics Agent
Pcoip Standard Agent
Jun 17, 2026
Aug 11, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
The support bundler in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows versions prior to 20.04.1 and 20.07.0 does not use hard coded paths for certain Windows binaries, which allows an attacker t...Show more
The support bundler in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows versions prior to 20.04.1 and 20.07.0 does not use hard coded paths for certain Windows binaries, which allows an attacker to gain elevated privileges via execution of a malicious binary placed in the system path.Show less
1Mozilla
3Firefox
Firefox EsrThunderbird
Jun 17, 2026
Aug 10, 2020
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. *Note: This issue only affected...Show more
Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.Show less
1Seafile
1Seafile Client
Jun 17, 2026
Jul 29, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
The seafile-client client 7.0.8 for Seafile is vulnerable to DLL hijacking because it loads exchndl.dll from the current working directory.
1Osisoft
9Pi Api
Pi Buffer SubsystemPi Connector+6 more
Jun 17, 2026
Jul 24, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at Windows system privile...Show more
In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at Windows system privilege level, resulting in unauthorized information disclosure, deletion, or modification.Show less
1360totalsecurity
1360 Total Security
Jun 17, 2026
Jul 21, 2020
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
In the version 12.1.0.1005 and below of 360 Total Security, when the Gamefolde calls GameChrome.exe, there exists a local privilege escalation vulnerability. An attacker who could exploit DLL hijacking to bypass the hips...Show more
In the version 12.1.0.1005 and below of 360 Total Security, when the Gamefolde calls GameChrome.exe, there exists a local privilege escalation vulnerability. An attacker who could exploit DLL hijacking to bypass the hips could execute arbitrary code on the Local system.Show less