Uncontrolled search path in the Intel(R) SDP Tool for Windows software all version may allow an authenticated user to po
Uncontrolled search path for some ACAT software maintained by Intel(R) for Windows before version 3.11.0 may allow an au
Uncontrolled search path for some Intel(R) Quartus(R) Prime Pro Edition software for Windows before version 24.2 may all
Uncontrolled search path in the Intel(R) Graphics Driver installers for versions 15.40 and 15.45 may allow an authentica
Uncontrolled search path for some Intel(R) Quartus(R) Prime Standard Edition software for Windows before version 23.1.1
Trial installer for McAfee Total Protection (legacy trial installer software) 16.0.53 allows local privilege escalation
An incorrect permissions assignment vulnerability in Trend Micro Deep Security 20.0 agents between versions 20.0.1-9400
Uncontrolled search path element in the installer for Zoom Workplace Desktop App for macOS before version 6.0.10 may all
IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installing like named jar fil
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec
There is an unsafe DLL loading vulnerability in ZTE ZXCLOUD iRAI. Due to the program failed to adequately validate the
An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authent
Whale browser Installer before 3.1.0.0 allows an attacker to execute a malicious DLL in the user environment due to impr
`gix-path` is a crate of the `gitoxide` project (an implementation of `git` written in Rust) dealing paths and their con
Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research
Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta
A library injection issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15, macOS Son
A vulnerability has been found in Mp3tag up to 3.26d and classified as problematic. This vulnerability affects unknown c
Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows
EMS SQL Manager 3.6.2 (build 55333) for Oracle allows DLL hijacking: a user can trigger the execution of arbitrary code
There is a DLL hijacking vulnerability in ZTE ZXCLOUD iRAI, an attacker could place a fake DLL file in a specific direc
SAP Product Lifecycle Costing Client (versions below 4.7.1) application loads on demand a DLL that is available with Win
A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file unde
An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker t
A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted P
Zoom Rooms for Windows installers before version 5.13.0 contain a local privilege escalation vulnerability. A local low-
Uncontrolled Search Path Element in Checkmk Agent in Tribe29 Checkmk before 2.1.0p1, before 2.0.0p25 and before 1.6.0p29
Uncontrolled search path element vulnerability exists in pg_ivm versions prior to 1.5.1. When refreshing an IMMV, pg_ivm
A vulnerability was reported where through modifying the scan variables, an authenticated user in Tenable products, that
Elevation of privilege issue in M-Files Installer versions before 22.6 on Windows allows user to gain SYSTEM privileges
Uncontrolled search path in the WULT software maintained by Intel(R) before version 1.0.0 (commit id 592300b) may allow
Uncontrolled search path for the Intel(R) AI Hackathon software before version 2.0.0 may allow an unauthenticated user t
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo
Usage of user controlled LD_LIBRARY_PATH in agent in Checkmk 2.2.0p10 up to 2.2.0p16 allows malicious Checkmk site user
IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0 could allow a loca
NVIDIA GPU Display Driver for Windows contains a vulnerability that allows Windows users with low levels of privilege to
Efs Software Easy Chat Server Version 3.1 was discovered to contain a DLL hijacking vulnerability via the component Text
Uncontrolled Search Path Element in GitHub repository bits-and-blooms/bloom prior to 3.3.1.
Cybereason EDR version 19.1.282 and above, 19.2.182 and above, 20.1.343 and above, and 20.2.X and above has a DLL hijack
This vulnerability allows local attackers to escalate privileges on affected installations of Windscribe. An attacker mu
In versions beginning with 7.2.2 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client Windo
Genymotion Desktop v3.3.2 was discovered to contain a DLL hijacking vulnerability that allows attackers to escalate priv
Infoblox BloxOne Endpoint for Windows through 2.2.7 allows DLL injection that can result in local privilege escalation.
An issue found in UwAmp v.1.1, 1.2, 1.3, 2.0, 2.1, 2.2, 2.2.1, 3.0.0, 3.0.1, 3.0.2 allows a remote attacker to execute a
ONLYOFFICE Docs through 7.3 on certain Linux distributions allows local users to gain privileges via a Trojan horse libg
An issue was discovered in Veritas NetBackup before 10.0 on Windows. A vulnerability in the way the client validates the
Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead t
Zoom Client for IT Admin macOS installers before version 5.13.5 contain a local privilege escalation vulnerability. A lo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Pa
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Pa
Frequently Asked Questions
What is CWE-427?
CWE-427 (CWE-427) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-427?
There are 1,525 CVE records associated with CWE-427 in our database. Of these, 26 are critical severity, 791 are high severity, and 347 are medium severity.
How can I protect against CWE-427 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-427 using AI-powered security agents.
Detect CWE-427 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-427 vulnerabilities across your infrastructure.
Get Started