Falhas do tipo CWE-427

863 resultados

Caminho de busca ou elemento não controlado

A aplicação procura por um recurso (arquivo, biblioteca, módulo) em múltiplos diretórios sem validar ou controlar a ordem de busca, permitindo que um atacante injete um arquivo malicioso em um caminho que será verificado primeiro. Isso leva a execução de código não autorizado ou bypass de controles de segurança.

Exemplo

Um programa em C carrega uma biblioteca dinâmica (DLL no Windows ou SO no Linux) procurando em diretórios listados em uma variável de ambiente. Se o atacante conseguir escrever um arquivo malicioso com o mesmo nome em um diretório anterior da busca (como o diretório atual), a aplicação carrega a versão maliciosa sem questionar.

Como mitigar

Use caminhos absolutos e hardcoded para recursos críticos; nunca confie em variáveis de ambiente para localizá-los. Valide hash ou assinatura digital de bibliotecas carregadas e restrinja permissões de escrita nos diretórios de busca apenas ao administrador.

CVE-2021-21011HIGHUncontrolled Search Path Element in Adobe Captivate 2019EPSS 2.0%CVE-2024-11859HIGHDLL Search Order Hijacking in ESET products for WindowsEPSS 2.0%CVE-2017-14010In SpiderControl MicroBrowser Windows XP, Vista 7, 8 and 10, Versions 1.6.30.144 and prior, an uncontrolled search path element vulnerabilitEPSS 2.0%CVE-2021-3840HIGHA dependency confusion vulnerability was reported in the Antilles open-source software prior to version 1.0.1 that could allow for remote coEPSS 2.0%CVE-2021-35982HIGHAdobe Reader DC Windows Installer Uncontrolled Search Path element could lead to Arbitrary Code ExecutionEPSS 1.8%CVE-2020-10616Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC does not specify the path of multiple imported .dll files. Therefore, an attacker canEPSS 1.7%CVE-2023-25143CRITICALAn uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote cEPSS 1.7%CVE-2022-32223Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnerability can be exploiEPSS 1.7%CVE-2018-14797Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 allow a specially crafted DLL file to be placed in the search path and loadedEPSS 1.7%CVE-2017-5175Advantech WebAccess 8.1 and earlier contains a DLL hijacking vulnerability which may allow an attacker to run a malicious DLL file within thEPSS 1.6%CVE-2021-21070MEDIUMPrivilege Escalation Vulnerability in Adobe RoboHelpEPSS 1.6%CVE-2022-43310HIGHAn Uncontrolled Search Path Element in Foxit Software released Foxit Reader v11.2.118.51569 allows attackers to escalate privileges when seaEPSS 1.6%CVE-2019-6534The uncontrolled search path element vulnerability in Gemalto Sentinel UltraPro Client Library ux32w.dll Versions 1.3.0, 1.3.1, and 1.3.2 enEPSS 1.5%CVE-2017-5170An Uncontrolled Search Path Element issue was discovered in Moxa SoftNVR-IA Live Viewer, Version 3.30.3122 and prior versions. An uncontrollEPSS 1.5%CVE-2018-13806A vulnerability has been identified in SIEMENS TD Keypad Designer (All versions). A DLL hijacking vulnerability exists in all versions of SIEPSS 1.4%CVE-2022-24767HIGHGitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user account.EPSS 1.4%CVE-2017-6051An Uncontrolled Search Path Element issue was discovered in BLF-Tech LLC VisualView HMI Version 9.9.14.0 and prior. The uncontrolled search EPSS 1.4%CVE-2017-6033A DLL Hijacking issue was discovered in Schneider Electric Interactive Graphical SCADA System (IGSS) Software, Version 12 and previous versiEPSS 1.3%CVE-2024-23054CRITICALAn issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listeEPSS 1.3%CVE-2020-5145SonicWall Global VPN client version 4.10.4.0314 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploEPSS 1.2%