Uncontrolled search path in some Intel(R) NUC 12 Pro Kits & Mini PCs - NUC12WS Intel(R) HID Event Filter Driver installa
Uncontrolled search path element in some Intel(R) XTU software before version 7.12.0.15 may allow an authenticated user
Uncontrolled search path in some Intel Battery Life Diagnostic Tool software before version 2.2.1 may allow an authentic
On versions beginning in 7.1.5 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client for Win
Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM)
A DLL hijacking vulnerability in Panda Security VPN for Windows prior to version v15.14.8 allows attackers to execute ar
An uncontrolled search path element vulnerability has been found on 4D and 4D server Windows executables applications, a
A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged
A command Injection Vulnerability in TA for mac-OS prior to version 5.7.9 allows local users to place an arbitrary file
Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugi
Uncontrolled search path element vulnerability in Plesk Installer affects version 3.27.0.0. A local attacker could execu
Uncontrolled Search Path Element vulnerability in Pandora FMS on all allows Leveraging/Manipulating Configuration File S
The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local use
McAfee Total Protection prior to 16.0.49 allows attackers to elevate user privileges due to DLL sideloading. This could
It is possible to sideload a compromised DLL during the installation at elevated privilege.
A vulnerability, which was classified as problematic, has been found in KMPlayer 4.2.2.73. This issue affects some unkno
General Electric MiCOM S1 Agile is vulnerable to an attacker achieving code execution by placing malicious DLL files in
A vulnerability classified as problematic was found in NotePad++ up to 8.1. Affected by this vulnerability is an unknown
A vulnerability has been found in PeaZip 9.4.0 and classified as problematic. Affected by this vulnerability is an unkno
Uncontrolled search path in the Intel(R) MacCPUID software before version 3.2 may allow an authenticated user to potenti
Uncontrolled search path element in the Intel(R) Unite(R) Client software for Mac before version 4.2.11 may allow an aut
Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files
Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earli
There exists a path traversal vulnerability in the Android Google Search app. This is caused by the incorrect usage of u
A misconfiguration in the node default path allows for local privilege escalation from a lower privileged user to the Sp
A vulnerability was found in Viscosity 1.6.7. It has been classified as critical. This affects an unknown part of the co
If an attacker manages to trick a valid user into loading a malicious DLL, the attacker may be able to achieve code exec
Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 co
The Zoom Rooms Installer for Windows prior to 5.12.6 contains a local privilege escalation vulnerability. A local low-pr
A DLL hijacking vulnerability in the MA Smart Installer for Windows prior to 5.7.7, which allows local users to execute
Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Dis
pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in p
A DLL hijacking vulnerability in the installed for Quick Heal Total Security prior to 12.1.1.27 allows a local attacker
An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow
Users have access to the directory where the installation repair occurs. Since the MS Installer allows regular users to
A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authen
A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5. McAfee Agent uses openssl.cnf during the build
AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop i
Uncontrolled search path in the Intel(R) GPA software before version 21.2 may allow an authenticated user to potentially
SAP Adaptive Server Enterprise (ASE) - version 16.0, installation makes an entry in the system PATH environment variable
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (
The LSP (Language Server Protocol) plugin in KDE Kate before 21.12.2 and KTextEditor before 5.91.0 tries to execute the
AXIS IP Utility before 4.18.0 allows for remote code execution and local privilege escalation by the means of DLL hijack
Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated
Trend Micro Password Manager (Consumer) installer version 5.0.0.1262 and below is vulnerable to an Uncontrolled Search P
The following Yokogawa Electric products contain insecure DLL loading issues. CENTUM CS 3000 versions from R3.08.10 to R
fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git re
The installer of WPS Office Version 10.8.0.6186 insecurely load VERSION.DLL (or some other DLLs), allowing an attacker t
The installer of WPS Office Version 10.8.0.5745 insecurely load shcore.dll, allowing an attacker to execute arbitrary co
WPS Presentation 11.8.0.5745 insecurely load d3dx9_41.dll when opening .pps files('current directory type' DLL loading).
Frequently Asked Questions
What is CWE-427?
CWE-427 (CWE-427) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-427?
There are 1,525 CVE records associated with CWE-427 in our database. Of these, 26 are critical severity, 791 are high severity, and 347 are medium severity.
How can I protect against CWE-427 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-427 using AI-powered security agents.
Detect CWE-427 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-427 vulnerabilities across your infrastructure.
Get Started