Skip to main content

Threats Tagged 'cwe-427'

View all threats tagged with 'cwe-427'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-427

Threats Tagged 'cwe-427'

Click on any threat for detailed analysis and mitigation recommendations

0

An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYSTEM via a planted executable resolved from the machine PATH. Assessment content at or below version 0.0.261.0 included a check that invoked the `code` command without a fully qualified path from a process running as SYSTEM. The command was resolved against the machine PATH environment variable at execution time. Where the machine PATH contained a directory writable by non-administrative users and ordered ahead of the legitimate Visual Studio Code installation, a local user could place an executable named `code` in that directory and cause the agent to execute it with SYSTEM privileges. The version range above refers to InsightVM assessment content versions, not Insight Agent versions. All Insight Agent versions were affected while running assessment content at or below 0.0.261.0. Assessment content is delivered to all Insight Agents via the Rapid7 Insight Platform independently of the Insight Agent version and is not customer-managed. This issue was resolved in assessment content version 0.0.269.0, which was made generally available on September 15, 2026. Remediation was deployed automatically and no customer action is required.

Join the discussion

IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker with local system access can manipulate the search path environment to execute untrusted or malicious code.

Join the discussion

A local privilege escalation vulnerability exists in the updater of Foxit PDF Editor/Reader due to unsafe loading of dynamic-link libraries from a user-writable directory during high-privilege operations. A local attacker could exploit this issue to execute code with elevated privileges.

Join the discussion

A local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a hardcoded configuration file path (C:\msys64) that is writable by unprivileged users, allowing for arbitrary code execution via the use_askpass directive, potentially allowing local privilege escalation.

Join the discussion

Privilege escalation due to weak configuration during package extraction process.

Join the discussion

CVE-2026-54916 is a high-severity vulnerability in the netbox-community devicetype-library, a collection of community-sourced device type definitions for NetBox. The issue arises from Python import path manipulation during test collection, allowing an unauthenticated contributor to add malicious modules that shadow legitimate ones. This enables arbitrary code execution on GitHub Actions runners, potentially leading to test-result tampering and unauthorized access to tokens or network resources. The vulnerability is fixed by a specific commit that addresses the import path handling.

Join the discussion

Dell Server Update Utility versions prior to 26.07.01 contain an Uncontrolled Search Path Element vulnerability (CWE-427). This flaw allows a low privileged local attacker to potentially execute code with elevated impact. The vulnerability affects Driver Pack For Windows OS before version 26.07.01. The CVSS 3.1 score is 8.2, indicating high severity with significant confidentiality, integrity, and availability impacts.

Join the discussion

CVE-2026-92838 is a DLL hijacking vulnerability in GeoVision Inc.'s GV-Remote E-map desktop application version 18.3.1. The application loads dynamic-link libraries from an unsafe search path, which allows a local attacker with write access to place a malicious DLL in a location searched before the legitimate one. Successful exploitation can lead to arbitrary code execution within the security context of the GV-Remote E-map process.

Join the discussion

pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architect. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the activation-service process. The product loads a library from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of SYSTEM. Was ZDI-CAN-29536.

Join the discussion

CVE-2026-92180 is a local privilege escalation vulnerability in pdfforge PDF Architect version 9.1.90.23122. The flaw exists in the activation-service process, which loads a library from an unsecured location, allowing an attacker with low-privileged code execution to escalate privileges to SYSTEM. This vulnerability has a high severity rating with a CVSS score of 7.8.

Join the discussion

Showing 1 to 10 of 194 results

Filters:Tag: cwe-427
Page 1 of 20
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses