Uncontrolled search path for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 within R
Uncontrolled search path for some Intel(R) Distribution for Python software installers before version 2025.2.0 within Ri
Uncontrolled search path for some Intel Driver and Support Assistant before version 25.2 within Ring 3: User Application
Uncontrolled search path for some System Event Log Viewer Utility software for all versions within Ring 3: User Applicat
Uncontrolled search path for some Intel(R) Graphics Software before version 25.22.1502.2 within Ring 3: User Application
Uncontrolled search path for the Instrumentation and Tracing Technology API (ITT API) software before version 3.25.4 wit
Uncontrolled search path for the Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User App
Uncontrolled search path for some FPGA Support Package for the Intel oneAPI DPC++C++ Compiler software before version 20
Uncontrolled search path for the Intel MPI Library before version 2021.16 within Ring 3: User Applications may allow an
A potential security vulnerability in Quartus® Prime Standard Edition Design Software may allow escalation of privilege.
A potential security vulnerability in Quartus® Prime Pro Edition Design Software may allow escalation of privilege.
The System Console Utility for Windows is vulnerable to a DLL planting vulnerability
Uncontrolled Search Path Element vulnerability in Altera High Level Synthesis Compiler on Windows allows Search Order Hi
The High Level Synthesis Compiler i++ command for Windows is vulnerable to a DLL planting vulnerability
A carefully crafted DLL, copied to C:\ProgramData\Synaptics folder, allows a local user to execute arbitrary code w
Mite for Perl before 0.013000 generates code with the current working directory ('.') added to the @INC path similar to
Sub::HandlesVia for Perl before 0.050002 allows untrusted code from the current working directory ('.') to be loaded sim
Linux::Statm::Tiny for Perl before 0.0701 allows untrusted code from the current working directory ('.') to be loaded si
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker
Arbitrary file write as the OSV-SCALIBR user on the host system via a path traversal vulnerability when using OSV-SCALIB
Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution
A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-
A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Exchan
An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citri
Uncontrolled Search Path Element in Arm Development Studio before 2025 may allow an attacker to perform a DLL hijacking
Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network.
Emerson ValveLink products use a fixed or controlled search path to find resources, but one or more locations in that
A flaw was found in Keycloak. The Keycloak guides recommend to not expose /admin path to the outside in case the install
A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configur
Rufus is a utility that helps format and create bootable USB flash drives. A DLL hijacking vulnerability in Rufus 4.6.22
DLL Search Order Hijacking vulnerability potentially allowed an attacker with administrator privileges to load a malicio
Uncontrolled Search Path Element vulnerability in OpenText Secure Content Manager on Windows allows DLL Side-Loading.Thi
PSEvents.exe in multiple Panda Security products runs hourly with SYSTEM privileges and loads DLL files from a user-writ
A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During th
DLL hijacking of all PE32 executables when run on Windows for ARM64 CPU architecture. This allows an attacker to execute
DLL search order hijacking vulnerability in the wave.exe executable for Windows 11, version 1.27.8. Exploitation of this
The Altiris Core Agent Updater package (AeXNSC.exe) is prone to an elevation of privileges vulnerability through DLL hij
In Seagate Toolkit on Windows a vulnerability exists in the Toolkit Installer prior to versions 2.35.0.6 where it attemp
In Zabbix Agent and Agent 2 on Windows, the OpenSSL configuration file is loaded from a path writable by low-privileged
Docker Desktop Installer.exe is vulnerable to DLL hijacking due to insecure DLL search order. The installer searches for
Socket Firewall is an HTTP/HTTPS proxy server that intercepts package manager requests and enforces security policies by
DLL Loading vulnerability in NEC Corporation RakurakuMusen Start EX All Verisons allows a attacker to manipulate the PC
When the service of ABP and AES is installed in a directory writable by non-administrative users, an attacker can replac
Uncontrolled Search Path Element vulnerability in Yandex Messenger on MacOS allows Search Order Hijacking.This issue aff
Uncontrolled Search Path Element vulnerability in Yandex Disk on MacOS allows Search Order Hijacking.This issue affects
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution du
Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user t
Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to e
Ashlar-Vellum Argon Uncontrolled Search Path Element Remote Code Execution Vulnerability. This vulnerability allows remo
Frequently Asked Questions
What is CWE-427?
CWE-427 (CWE-427) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-427?
There are 1,525 CVE records associated with CWE-427 in our database. Of these, 26 are critical severity, 791 are high severity, and 347 are medium severity.
How can I protect against CWE-427 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-427 using AI-powered security agents.
Detect CWE-427 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-427 vulnerabilities across your infrastructure.
Get Started