CWE-427: CWE-427
Yearly Trend
Top Affected Vendors
All CWE-427 CVEs (401)
This CVE describes a local privilege escalation vulnerability in Palo Alto Networks Cortex XDR agent on Windows. It allows authenticated local Windows...
Jun 10, 2021This vulnerability in Intel NUC M15 Laptop Kit Driver Pack software allows authenticated local users to escalate privileges by exploiting an uncontrol...
Jun 9, 2021This is a DLL hijacking vulnerability in Overwolf's installer that allows attackers to execute arbitrary code with user privileges by placing a malici...
May 24, 2021This vulnerability allows attackers to load malicious DLL files via an uncontrolled search path in the OpenSSL component of Bitdefender GravityZone Bu...
May 18, 2021CVE-2020-24755 is a DLL hijacking vulnerability in Ubiquiti UniFi Video software that allows attackers to execute arbitrary code by placing malicious ...
May 17, 2021This vulnerability allows attackers to replace the NVENC.dll file in Teradici PCoIP Graphics Agent for Windows, enabling pixel data redirection to una...
May 13, 2021This vulnerability allows local attackers to escalate privileges by exploiting a DLL search path issue in Lenovo PCManager. Attackers can place malici...
Apr 27, 2021Trend Micro Password Manager 5 (Consumer) has a DLL hijacking vulnerability during installation that allows attackers to place malicious DLLs in insta...
Apr 13, 2021This vulnerability allows attackers to execute arbitrary code on affected systems by exploiting DLL hijacking in Bosch BVMS and related products. It a...
Mar 25, 2021This vulnerability allows attackers to execute arbitrary code on systems running vulnerable versions of the Bosch Video Client installer. Attackers ca...
Mar 25, 2021This vulnerability allows attackers to execute arbitrary code on systems running vulnerable versions of Bosch Monitor Wall installer. Attackers can ac...
Mar 25, 2021This vulnerability allows DLL hijacking in Zoho ManageEngine Desktop Central MSP, enabling attackers to execute arbitrary code with SYSTEM privileges....
Mar 18, 2021This vulnerability in Utimaco SecurityServer allows authenticated non-administrator users to manipulate binaries due to overly permissive file/folder ...
Mar 18, 2021This CVE describes a DLL injection vulnerability in Dell SupportAssist software that allows local low-privileged users to execute arbitrary code with ...
Mar 12, 2021This vulnerability in Intel FPGA OPAE Driver for Linux allows authenticated local users to escalate privileges due to improper conditions checking. It...
Feb 17, 2021CVE-2020-35145 is a local privilege escalation vulnerability in Acronis True Image for Windows, caused by DLL hijacking in multiple components. It all...
Jan 29, 2021A DLL hijacking vulnerability in Trend Micro HouseCall for Home Networks allows local attackers to escalate privileges and execute arbitrary code by p...
Jan 27, 2021This vulnerability allows authenticated local attackers on Windows systems with Cisco AnyConnect Secure Mobility Client to perform DLL injection attac...
Jan 13, 2021OpenClaw versions 2.0.0-beta3 through 2026.2.13 contain a path traversal vulnerability in the hook transform module loading mechanism. Attackers with ...
Mar 5, 2026This CVE describes an uncontrolled search path element vulnerability in Mitsubishi Electric's MILCO.S lighting control system applications. It allows ...
Nov 18, 2025This vulnerability allows local attackers to execute arbitrary code with administrator privileges by tricking a user with admin rights into mounting a...
Aug 4, 2025CVE-2025-23177 is a path traversal vulnerability (CWE-427) that allows attackers to load malicious DLLs or executables from untrusted locations. This ...
Apr 29, 2025This vulnerability allows attackers to manipulate Pandora FMS's configuration file search paths, potentially accessing the server configuration file a...
Nov 23, 2023This vulnerability allows authenticated attackers within the network to replace temporary executable files during SAP Business Objects installation wi...
Aug 8, 2023A local privilege escalation vulnerability in Sophos Intercept X for Windows installer allows local users to gain SYSTEM-level privileges when the ins...
Jul 17, 2025This path traversal vulnerability in Safearchive allows attackers to write arbitrary files during archive extraction by exploiting symbolic links on c...
Nov 4, 2024This vulnerability in Git for Windows allows local authenticated users to place malicious configuration files in C:\etc\connectrc, which Git's connect...
Apr 25, 2023This vulnerability in Go on Windows allows command injection and remote code execution when using 'go get' to fetch modules that use cgo. Attackers ca...
Jan 26, 2021Dell Alienware Command Center versions before 6.2.7.0 have a path traversal vulnerability where local attackers can place malicious files in the appli...
Apr 10, 2024This CVE describes a local privilege escalation vulnerability in Acronis Cyber Protect Cloud Agent for Windows. Attackers can exploit DLL hijacking to...
Mar 6, 2026Dell Repository Manager versions before 3.4.8 have a path traversal vulnerability where attackers with local access can execute arbitrary code and esc...
Feb 23, 2026This vulnerability allows local attackers to escalate privileges on PDF-XChange Editor installations by exploiting an uncontrolled search path element...
Feb 20, 2026A DLL hijacking vulnerability in AMD Doc Nav software allows local attackers to escalate privileges by placing malicious DLLs in directories searched ...
Feb 12, 2026A DLL hijacking vulnerability in AMD's Vivado design suite allows local attackers to escalate privileges by placing malicious DLLs in directories sear...
Feb 11, 2026This vulnerability allows local attackers with initial low-privileged access to escalate privileges by exploiting Discord's insecure file loading mech...
Jan 23, 2026D-Link D-View 8 installer versions 2.0.1.107 and below contain a DLL preloading vulnerability where the installer loads version.dll from its execution...
Jan 21, 2026This vulnerability in NVIDIA Nsight Visual Studio for Windows allows attackers to execute arbitrary code with the same privileges as the Nsight Monito...
Jan 20, 2026MailEnable versions before 10.54 have a DLL hijacking vulnerability where the administrative executable loads MEAINFY.DLL from its directory without p...
Dec 9, 2025This CVE describes a DLL hijacking vulnerability in Acronis True Image products for Windows that allows local attackers to escalate privileges. Attack...
Sep 30, 2025This vulnerability allows non-privileged local users on Windows systems to execute arbitrary code by writing a malicious openssl.cnf configuration fil...
May 13, 2025BleachBit for Windows up to version 4.6.2 is vulnerable to DLL hijacking, allowing attackers to execute arbitrary code by placing a malicious uuid.dll...
Apr 15, 2025This vulnerability allows an authorized attacker to exploit an uncontrolled search path element in Visual Studio Tools for Applications and SQL Server...
Apr 12, 2025This DLL hijacking vulnerability in NI LabVIEW allows attackers to execute arbitrary code by placing a malicious DLL in an uncontrolled search path. I...
Apr 9, 2025This vulnerability allows an authenticated attacker with local access to a system running Visual Studio to bypass intended access controls and elevate...
Apr 8, 2025This vulnerability in Visual Studio Code allows an authorized attacker to execute arbitrary code with elevated privileges by exploiting an uncontrolle...
Mar 11, 2025This vulnerability allows an authorized attacker to exploit an uncontrolled search path element in Visual Studio to execute arbitrary code with elevat...
Mar 11, 2025This vulnerability allows an authorized attacker to exploit an uncontrolled search path element in Visual Studio to execute arbitrary code with elevat...
Mar 11, 2025This vulnerability involves insecure DLL loading in the USB-CONVERTERCABLE DRIVER, allowing local attackers to potentially execute arbitrary code or d...
Feb 18, 2025This vulnerability allows local attackers to exploit insecure DLL loading in HVAC Energy Saving Program, potentially leading to information disclosure...
Feb 18, 2025This DLL hijacking vulnerability in AMD Integrated Management Technology (AIM-T) Manageability Service allows attackers to place malicious DLLs in spe...
Feb 11, 2025About CWE-427 (CWE-427)
Our database tracks 401 CVEs classified as CWE-427, with 7 rated critical and 286 rated high severity. The average CVSS score for CWE-427 vulnerabilities is 7.5.
External reference: View CWE-427 on MITRE CWE →
Monitor CWE-427 Vulnerabilities
Get alerted when new CWE-427 CVEs affect your infrastructure.
Start Monitoring Free