Client side code execution in gitlab-vscode-extension v3.15.0 and earlier allows attacker to execute code on user system
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). The software insecurely loads libraries
Adobe After Effects version 18.1 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An unau
Improper access control vulnerability in the repair process for McAfee Agent for Windows prior to 5.7.4 could allow a lo
AnyDesk before 6.1.0 on Windows, when run in portable mode on a system where the attacker has write access to the applic
SaferVPN for Windows Ver 5.0.3.3 through 5.0.4.15 could allow local privilege escalation from low privileged users to SY
Untrusted search path vulnerability in the installer of SKYSEA Client View Ver.1.020.05b to Ver.16.001.01g allows an att
A vulnerability in the Network Access Manager and Web Security Agent components of Cisco AnyConnect Secure Mobility Clie
A vulnerability in the loading mechanism of specific DLLs of Cisco Advanced Malware Protection (AMP) for Endpoints for W
A DLL hijacking vulnerability Trend Micro HouseCall for Home Networks version 5.3.1063 and below could allow an attacker
Acronis True Image for Windows prior to 2021 Update 3 allowed local privilege escalation due to a DLL hijacking vulnerab
A vulnerability has been identified in PCS neo (Administration Console) (All versions < V3.1), TIA Portal (V15, V15.1 an
Improper conditions check in the Intel(R) FPGA OPAE Driver for Linux before kernel version 4.17 may allow an authenticat
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows c
ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain dir
Untrusted search path vulnerability in Installer of MagicConnect Client program distributed before 2021 March 1 allows a
Dell SupportAssist Client for Consumer PCs versions 3.7.x, 3.6.x, 3.4.x, 3.3.x, Dell SupportAssist Client for Business P
Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions fo
Rockwell Automation DriveTools SP v5.13 and below and Drives AOP v4.12 and below both contain a vulnerability that a loc
The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinvent
The unofficial C/C++ Advanced Lint extension before 1.9.0 for Visual Studio Code allows attackers to execute arbitrary b
In Chris Walz bit before 1.0.5 on Windows, attackers can run arbitrary code via a .exe file in a crafted repository.
Loading a DLL through an Uncontrolled Search Path Element in Bosch IP Helper up to and including version 1.00.0008 poten
Loading a DLL through an Uncontrolled Search Path Element in Bosch BVMS and BVMS Viewer in versions 10.1.0, 10.0.1, 10.0
Loading a DLL through an Uncontrolled Search Path Element in the Bosch Video Recording Manager installer up to and inclu
Loading a DLL through an Uncontrolled Search Path Element in the Bosch Video Client installer up to and including versio
Loading a DLL through an Uncontrolled Search Path Element in the Bosch Configuration Manager installer up to and includi
Loading a DLL through an Uncontrolled Search Path Element in the Bosch Monitor Wall installer up to and including versio
Calling an executable through an Uncontrolled Search Path Element in the Bosch Video Streaming Gateway installer up to a
Dell Peripheral Manager 1.3.1 or greater contains remediation for a local privilege escalation vulnerability that could
Trend Micro Password Manager version 5 (Consumer) is vulnerable to a DLL Hijacking vulnerability which could allow an at
An issue was discovered in Forescout CounterACT before 8.1.4. A local privilege escalation vulnerability is present in t
A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow privil
Teradici PCoIP Graphics Agent for Windows prior to 21.03 does not validate NVENC.dll. An attacker could replace the .dll
In Ubiquiti UniFi Video v3.10.13, when the executable starts, its first library validation is in the current directory.
Uncontrolled Search Path Element vulnerability in the openssl component as used in Bitdefender GravityZone Business Secu
Untrusted search path vulnerability in the installers of ScanSnap Manager prior to versions V7.0L20 and the Software Dow
Untrusted search path vulnerability in The Installer of Overwolf 2.168.0.n and earlier allows an attacker to gain privil
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local us
Uncontrolled search path in the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may allow an
Uncontrolled search path element in the installer for the Intel(R) Rapid Storage Technology software, before versions 17
A local privilege escalation vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that e
On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, a DLL hijacking issue exists in cachecleaner.dll in
TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations.
VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App
When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to ope
OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL c
OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL confi
dandavison delta before 0.8.3 on Windows resolves an executable's pathname as a relative path from the current directory
VMware Thinapp version 5.x prior to 5.2.10 contain a DLL hijacking vulnerability due to insecure loading of DLLs. A mali
Frequently Asked Questions
What is CWE-427?
CWE-427 (CWE-427) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-427?
There are 1,525 CVE records associated with CWE-427 in our database. Of these, 26 are critical severity, 791 are high severity, and 347 are medium severity.
How can I protect against CWE-427 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-427 using AI-powered security agents.
Detect CWE-427 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-427 vulnerabilities across your infrastructure.
Get Started