CWE-426

High likelihood

Untrusted Search Path

Parent: CWE-642 - External Control of Critical State Data

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

657 vulnerabilities with CWE-426
CVE-2023-41840 HIGH
FortiClientWindows 7.0.9 - DLL Hijack via OpenSSL Engine Library Search Path
CVSS 7.8
CVE-2023-36422 HIGH
Microsoft Windows Defender - Privilege Escalation
CVSS 7.8
CVE-2023-36393 HIGH
Microsoft Windows UI App Core - Remote Code Execution
CVSS 7.8
CVE-2023-41766 HIGH
Windows CSRSS - Untrusted Search Path Elevation of Privilege
CVSS 7.8
CVE-2023-36780 HIGH
Skype for Business Server - Remote Code Execution via Untrusted Search Path
CVSS 7.2
CVE-2023-36778 HIGH
Microsoft Exchange Server - Remote Code Execution via Untrusted Search Path
CVSS 8.0
CVE-2023-39201 HIGH
CleanZoom <07/24/2023 - Privilege Escalation
CVSS 7.2
CVE-2023-4736 HIGH
vim < 9.0.1833 - Untrusted Search Path
CVSS 7.8
CVE-2023-40590 HIGH
GitPython < 3.1.32 - Untrusted Search Path via Git Executable Resolution
CVSS 7.8
CVE-2023-41105 HIGH
Python 3.11.0-3.11.4 - Untrusted Search Path via os.path.normpath()
CVSS 7.5
CVE-2023-29299 MEDIUM
Adobe Acrobat Reader <23.003.20244 & <20.005.30467 - DoS
CVSS 4.7
CVE-2023-39212 HIGH
Zoom Rooms for Windows <5.15.5 - DoS
CVSS 7.9
CVE-2023-36898 HIGH
Microsoft Tablet Windows UI App Core - Remote Code Execution
CVSS 7.8
CVE-2023-36540 HIGH
Zoom Desktop Client for Windows <5.14.5 - Privilege Escalation
CVSS 7.3
CVE-2023-36538 HIGH
Zoom Rooms for Windows <5.15.0 - Privilege Escalation
CVSS 8.4
CVE-2023-36536 HIGH
Zoom Rooms for Windows <5.15.0 - Privilege Escalation
CVSS 8.2
CVE-2023-35343 HIGH
Windows Geolocation Service - Remote Code Execution
CVSS 7.8
CVE-2023-34119 HIGH
Zoom Rooms for Windows <5.15.0 - Privilege Escalation
CVSS 8.2
CVE-2023-34145 HIGH
Trend Micro Apex One - Privilege Escalation
CVSS 7.8
CVE-2023-34144 HIGH
Trend Micro Apex One - Privilege Escalation
CVSS 7.8
CVE-2023-30330 CRITICAL
SoftExpert Excellence Suite 2.0-2.1.2 - Local File Inclusion via defaultframe_filter.php
CVSS 9.8
CVE-2023-29790 HIGH
kodbox 1.2.0-1.3.7 - Sensitive Information Leakage
CVSS 7.5
CVE-2023-28143 MEDIUM
Qualys Cloud Agent 2.5.1-75-3.7 - Local Privilege Escalation via Incorrect File Permissions
CVSS 6.7
CVE-2023-27771 HIGH
Wondershare Creative Centerr 1.0.8 - Remote Code Execution via wondershareCC_setup_full10819.exe
CVSS 7.8
CVE-2023-27770 HIGH
Wondershare Edraw Max 12.0.4 - Remote Code Execution via Setup Executable
CVSS 7.8
Details
Vulnerabilities 657
Exploit Likelihood High