Vulnerabilities > Uncontrolled Search Path Element

DATE CVE VULNERABILITY TITLE RISK
2022-02-09 CVE-2021-33101 Uncontrolled Search Path Element vulnerability in Intel Graphics Performance Analyzers
Uncontrolled search path in the Intel(R) GPA software before version 21.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-427
4.6
2022-02-09 CVE-2022-22528 Uncontrolled Search Path Element vulnerability in SAP Adaptive Server Enterprise 16.0
SAP Adaptive Server Enterprise (ASE) - version 16.0, installation makes an entry in the system PATH environment variable in Windows platform which, under certain conditions, allows a Standard User to execute malicious Windows binaries which may lead to privilege escalation on the local system.
local
low complexity
sap CWE-427
7.8
2022-02-04 CVE-2020-12891 Uncontrolled Search Path Element vulnerability in AMD Radeon PRO Software and Radeon Software
AMD Radeon Software may be vulnerable to DLL Hijacking through path variable.
local
amd CWE-427
4.4
2022-02-04 CVE-2021-44205 Uncontrolled Search Path Element vulnerability in Acronis Cyber Protect Home Office and True Image
Local privilege escalation due to DLL hijacking vulnerability.
4.4
2022-02-04 CVE-2021-44206 Uncontrolled Search Path Element vulnerability in Acronis Cyber Protect Home Office and True Image
Local privilege escalation due to DLL hijacking vulnerability in Acronis Media Builder service.
4.4
2022-01-28 CVE-2021-44463 Uncontrolled Search Path Element vulnerability in Emerson Deltav
Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Distributed Control System Controllers and Workstations (All versions) when some DeltaV services are started.
6.9
2022-01-19 CVE-2022-0166 Uncontrolled Search Path Element vulnerability in Mcafee Agent
A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5.
local
low complexity
mcafee CWE-427
7.8
2022-01-12 CVE-2022-0015 Uncontrolled Search Path Element vulnerability in Paloaltonetworks Cortex XDR Agent
A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authenticated local user to execute programs with elevated privileges.
local
low complexity
paloaltonetworks CWE-427
4.6
2022-01-11 CVE-2022-0129 Uncontrolled Search Path Element vulnerability in Mcafee Techcheck 3.0.0.17
Uncontrolled search path element vulnerability in McAfee TechCheck prior to 4.0.0.2 allows a local administrator to load their own Dynamic Link Library (DLL) gaining elevation of privileges to system user.
local
low complexity
mcafee CWE-427
6.7
2022-01-10 CVE-2021-30360 Uncontrolled Search Path Element vulnerability in Checkpoint Endpoint Security
Users have access to the directory where the installation repair occurs.
local
low complexity
checkpoint CWE-427
7.2