Uncontrolled search path for some Intel(R) Server Firmware Update Utility Software before version 16.0.12. within Ring 3
Uncontrolled search path for some AI Playground software before version 3.0.0 alpha within Ring 3: User Applications may
Unsafe OpenSSL initialization within some AMD optional tools may allow a local user-privileged attacker to inject a mali
Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level contr
An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (
MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading mali
MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading a ma
Potential security vulnerabilities have been identified in the HP One Agent for certain HP PC products, which might all
To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is
Local privilege escalation by loading DLLs from a shared temporary directory in ANSSI’s DFIR-ORC, versions 10.2.7 and pr
An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy
A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is lo
Uncontrolled search paths in the Vitis™ Embedded Single File Download (SFD) for local Windows installation could allow a
Uncontrolled search paths in Vitis™ Unified installation path on local Windows machines could allow DLL injection into t
A DLL hijacking vulnerability in AMD Power Design Manager could allow a malicious local attacker to escalate privileges
Uncontrolled search path for some EquiTriton before version f5ddbb5 within Ring 3: User Applications may allow an escala
Uncontrolled search path for some Approximate Bayesian Inference Framework before version on commit #484c949 within Ring
Uncontrolled search path for some Hardware-Aware-Automated-MachineLearning NA before version 45cd723 within Ring 3: User
A DLL hijacking vulnerability within the AMD Ryzen Master installation could allow a local user-privileged attacker to e
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS device
When Zabbix Agent was installed on Windows into a custom installation directory, the installer did not verify whether th
SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sa
Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection. An attacker could compile a .dylib file a
FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placin
IBM Cognos Dashboards 4.0.7 and 5.0.0 on Cloud Pak for Data could allow a remote attacker to perform unauthorized action
Privilege escalation in jar_signature agent plugin in Checkmk versions <2.4.0b7 (beta), <2.3.0p32, <2.2.0p42, and 2.1.0p
An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacke
IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified library call in IBM Fa
Uncontrolled Search Path Element vulnerability in Salesforce Salesforce CLI on Windows allows Replace Trusted Executable
DigiSign DigiSigner ONE 1.0.4.60 allows DLL Hijacking.
NVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled search path.
DLL hijacking vulnerabilities, caused by an uncontrolled search path in Silicon Labs (8-bit) IDE installer can lead to p
DLL hijacking vulnerabilities, caused by an uncontrolled search path in Configuration Wizard 2 installer can lead to pri
DLL hijacking vulnerabilities, caused by an uncontrolled search path in Flash Programming Utility installer can lead to
DLL hijacking vulnerabilities, caused by an uncontrolled search path in the ToolStick installer can lead to privileg
DLL hijacking vulnerabilities, caused by an uncontrolled search path in the CP210 VCP Win 2k installer can lead
DLL hijacking vulnerabilities, caused by an uncontrolled search path in the CP210x VCP Windows installer can lead t
DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress Dev Kit installer can lead
DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress 4 SDK installer can lead to
DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress SDK installer can lead to p
DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress Win 98SE Dev Kit installer can lea
Improper authentication of library files in the Eaton IPP software installer could lead to arbitrary code execution of a
Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code exec
IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user with the capability to compile or restore a program to gain elevated pri
An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script
Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to execute malicious code. N
DLL hijacking vulnerability in Evope Collector 1.1.6.9.0 and related components load the wtsapi32.dll library from an un
NVIDIA Display Driver contains a vulnerability where an uncontrolled DLL loading path might lead to arbitrary denial of
NVIDIA NVApp for Windows contains a vulnerability in the installer, where a local attacker can cause a search path eleme
Frequently Asked Questions
What is CWE-427?
CWE-427 (CWE-427) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-427?
There are 1,525 CVE records associated with CWE-427 in our database. Of these, 26 are critical severity, 791 are high severity, and 347 are medium severity.
How can I protect against CWE-427 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-427 using AI-powered security agents.
Detect CWE-427 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-427 vulnerabilities across your infrastructure.
Get Started