This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Pa
An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During SDK installation, certutil.exe is called by the
Local privilege escalation due to a DLL hijacking vulnerability. The following products are affected: Acronis Snap Deplo
CyberGhostVPN Windows Client before v8.3.10.10015 was discovered to contain a DLL injection vulnerability via the compon
A DLL Hijacking issue discovered in Soft-o Free Password Manager 1.1.20 allows attackers to create arbitrary DLLs leadin
A maliciously crafted DLL file can be forced to read beyond allocated boundaries in Autodesk InfraWorks 2023, and 2021 w
A maliciously crafted DLL file can be forced to write beyond allocated boundaries in the Autodesk installer when parsing
Trend Micro Security 2021, 2022, and 2023 (Consumer) are vulnerable to a DLL Hijacking vulnerability which could allow a
In Keysight Geolocation Server v2.4.2 and prior, a low privileged attacker could create a local ZIP file containin
An installer that loads or executes files using an unconstrained search path may be vulnerable to substitute files under
A vulnerability has been identified in Siemens Software Center (All versions < V3.0). A DLL Hijacking vulnerability coul
An issue in Diebold Nixdorf Vynamic View Console v.5.3.1 and before allows a local attacker to execute arbitrary code vi
A DLL hijacking vulnerability has been discovered in OutSystems Service Studio 11 11.53.30 build 61739. When a user open
An uncontrolled search path vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow an a
ForeScout NAC SecureConnector version 11.2 - CWE-427: Uncontrolled Search Path Element
A vulnerability classified as critical has been found in Caphyon Advanced Installer 19.7. This affects an unknown part o
A vulnerability was found in XINJE XDPPro up to 3.7.17a. It has been rated as critical. Affected by this issue is some u
An uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local a
An uncontrolled search path element vulnerability has been found in the Duet Display product, affecting version 2.5.9.1.
A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller a
A maliciously crafted DLL file can be forced to install onto a non-default location, and attacker can overwrite parts of
An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msim
An Untrusted search path vulnerability in Sohu Video Player 7.0.15.0 allows local users to gain escalated privileges thr
An Untrusted search path vulnerability in NetEase CloudMusic 2.10.4 for Windows allows local users to gain escalated pri
DLL Hijacking vulnerability in Huddly HuddlyCameraService before version 8.0.7, not including version 7.99, due to the i
EzViz Studio v2.2.0 is vulnerable to DLL hijacking.
DLL hijacking vulnerability in TTplayer version 7.0.2, allows local attackers to escalate privileges and execute arbitra
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec
In BeyondTrust Privilege Management for Windows (aka PMfW) through 5.7, a SYSTEM installation causes Cryptbase.dll to be
SAP Business Objects Installer - versions 420, 430, allows an authenticated attacker within the network to overwrite an
Uncontrolled Search Path Element vulnerability in Pandora FMS on all allows Leveraging/Manipulating Configuration File S
Git for Windows, the Windows port of Git, ships with an executable called `connect.exe`, which implements a SOCKS5 proxy
Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an u
In AFL++ 4.05c, the CmpLog component uses the current working directory to resolve and execute unprefixed fuzzing target
An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. It is used to install drivers from several different v
An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. It is installed with insecure permissions (full write
In CODESYS Development System versions from 3.5.17.0 and prior to 3.5.19.20 a vulnerability allows for execution of bina
Certain HP and Samsung Printer software packages may potentially be vulnerable to elevation of privilege due to Uncontro
A DLL hijacking vulnerability in Samsung Memory Card & UFD Authentication Utility PC Software before 1.0.1 could allow a
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec
SonicWall NetExtender Windows (32-bit and 64-bit) client 10.2.336 and earlier versions have a DLL Search Order Hijacking
NVIDIA GPU Display Driver for Windows contains a vulnerability where an uncontrolled search path element may allow an at
BleachBit cleans files to free disk space and to maintain privacy. BleachBit for Windows up to version 4.4.2 is vulnerab
Multiple DLL Search Order Hijack vulnerabilities were addressed in the SanDisk Security Installer for Windows that could
Git for Windows is the Windows port of Git. Prior to version 2.40.1, any user of Git CMD who starts the command in an un
McAfee Safe Connect before 2.16.1.126 may allow an adversary with system privileges to achieve privilege escalation by l
Dell OpenManage Server Administrator (OMSA) version 10.3.0.0 and earlier contains a DLL Injection Vulnerability. A loca
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Captura up to 8.0.0. It has been declared as critical. This
In Splunk Enterprise versions earlier than 8.2.12, 9.0.6, and 9.1.1, a dynamic link library (DLL) that ships with Splunk
Facsimile Support for IBM i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqual
Frequently Asked Questions
What is CWE-427?
CWE-427 (CWE-427) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-427?
There are 1,525 CVE records associated with CWE-427 in our database. Of these, 26 are critical severity, 791 are high severity, and 347 are medium severity.
How can I protect against CWE-427 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-427 using AI-powered security agents.
Detect CWE-427 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-427 vulnerabilities across your infrastructure.
Get Started