Uncontrolled search path in the Intel(R) XTU software before version 7.3.0.33 may allow an authenticated user to potenti
Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnera
ShowMyPC 3606 on Windows suffers from a DLL hijack vulnerability. If an attacker overwrites the file %temp%\ShowMyPC\-Sh
AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijac
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec
InstallBuilder Qt installers built with versions previous to 22.10 try to load DLLs from the installer binary parent dir
ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hija
The application searches for a library dll that is not found. If an attacker can place a dll with this name, then the at
IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execut
The Zoom Opener installer is downloaded by a user from the Launch meeting page, when attempting to join a meeting withou
Adobe Creative Cloud Desktop version 2.7.0.13 (and earlier) is affected by an Uncontrolled Search Path Element vulnerabi
Dell GeoDrive, versions prior to 2.2, contains Multiple DLL Hijacking Vulnerabilities. A low privilege attacker could po
If Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched t
Uncontrolled Search Path Element in software for Intel(R) PROSet/Wireless Wi-Fi in Windows 10 and 11 may allow a privile
VMware Tools for Windows (11.x.y and 10.x.y prior to 12.0.0) contains an uncontrolled search path vulnerability. A malic
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries. Uncontrolled
A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that e
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affe
Uncontrolled search path in the software installer for Intel(R) System Studio for all versions, may allow an authenticat
Uncontrolled search path in the Intel(R) VTune(TM) Profiler software before version 2022.2.0 may allow an authenticated
Uncontrolled search path element in the PresentMon software maintained by Intel(R) before version 1.7.1 may allow an aut
Uncontrolled search path element in the Intel(R) Quartus Prime Standard edition software before version 21.1 Patch 0.02s
Uncontrolled search path element in the Intel(R) Advanced Link Analyzer Pro before version 22.2 and Standard edition sof
Uncontrolled search path element in the Intel(R) Glorp software may allow an authenticated user to potentially enable es
Uncontrolled search path in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 bef
An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8. This all
Untrusted search path vulnerability in Baidunetdisk Version 7.4.3 and earlier allows an attacker to gain privileges via
An installer search patch element vulnerability in Trend Micro Portable Security 3.0 Pro, 3.0 and 2.0 could allow a loca
Multiple DLL hijacking vulnerabilities via the components instup.exe and wsc_proxy.exe in Avast Premium Security before
A vulnerability was found in XAMPP 7.1.1-0-VC14. It has been classified as problematic. Affected is an unknown function
A vulnerability was found in InnoSetup Installer. It has been declared as problematic. Affected by this vulnerability is
DLL hijacking vulnerability in Smart Switch PC prior to version 4.2.22022_4 allows attacker to execute abitrary code.
DLL hijacking vulnerability in Kies prior to version 2.6.4.22014_2 allows attacker to execute abitrary code.
DLL hijacking vulnerability in Gear IconX PC Manager prior to version 2.1.220405.51 allows attacker to execute arbitrary
DLL hijacking vulnerability in KiesWrapper in Samsung Kies prior to version 2.6.4.22043_1 allows attacker to execute arb
DLL hijacking vulnerability in Smart Switch PC prior to version 4.3.22083_3 allows attacker to execute arbitrary code.
Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-
Uncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute a
Dell EMC PowerStore, Versions prior to v3.0.0.0 contain a DLL Hijacking vulnerability in PSTCLI. A local attacker can po
When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to une
Uncontrolled search path element vulnerability in Samsung Android USB Driver windows installer program prior to version
A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default pa
A vulnerability classified as problematic was found in Python 2.7.13. This vulnerability affects unknown code of the com
DLL hijacking vulnerability in Samsung Update Setup prior to version 2.2.9.50 allows attackers to execute arbitrary code
Windows 32-bit versions of the Zoom Client for Meetings before 5.12.6 and Zoom Rooms for Conference Room before version
git-bug before 0.7.2 has an Uncontrolled Search Path Element. It will execute git.bat from the current directory in cert
Many of the services used by the affected product do not specify full paths for the DLLs they are loading. An attacker c
The FTL Server (tibftlserver), FTL C API, FTL Golang API, FTL Java API, and FTL .Net API components of TIBCO Software In
The Enterprise Message Service Server (tibemsd), Enterprise Message Service Central Administration (tibemsca), Enterpris
A dependency confusion vulnerability was reported in the Antilles open-source software prior to version 1.0.1 that could
Frequently Asked Questions
What is CWE-427?
CWE-427 (CWE-427) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-427?
There are 1,525 CVE records associated with CWE-427 in our database. Of these, 26 are critical severity, 791 are high severity, and 347 are medium severity.
How can I protect against CWE-427 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-427 using AI-powered security agents.
Detect CWE-427 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-427 vulnerabilities across your infrastructure.
Get Started