CWE-427: CWE-427

401
Total CVEs
7
Critical
286
High
7.5
Avg CVSS

Yearly Trend

2026
36
2025
151
2024
88
2023
45
2022
26

Top Affected Vendors

1 Intel 37
2 Acronis 13
3 Dell 11
4 Mailenable 10
5 Lenovo 8
6 Microsoft 8
7 Adobe 8
8 Trendmicro 7
9 Siemens 7
10 Nvidia 6

All CWE-427 CVEs (401)

CVE-2025-14596
6.7

This CVE describes a Search Order Hijacking vulnerability in Altera Quartus Prime Pro Installer on Windows. Attackers can place malicious DLLs in dire...

Jan 7, 2026
CVE-2025-14599
6.7

This CVE describes a Search Order Hijacking vulnerability in Altera Quartus Prime installers on Windows. Attackers can place malicious DLLs in directo...

Jan 7, 2026
CVE-2025-14605
6.7

This vulnerability allows attackers to hijack the search path used by Altera Quartus Prime Pro's System Console modules on Windows, potentially loadin...

Jan 7, 2026
CVE-2025-13665
6.7

CVE-2025-13665 is a DLL planting vulnerability in the System Console Utility for Windows that allows attackers to execute arbitrary code by placing ma...

Dec 12, 2025
CVE-2025-13669
6.7

This vulnerability allows attackers to execute arbitrary code by placing malicious DLLs in directories searched by the Altera High Level Synthesis Com...

Dec 12, 2025
CVE-2025-13670
6.7

This DLL planting vulnerability in the High Level Synthesis Compiler i++ command for Windows allows attackers to execute arbitrary code by placing mal...

Dec 12, 2025
CVE-2025-13668
6.7

A privilege escalation vulnerability in Quartus Prime Pro Edition Design Software could allow local attackers to gain elevated privileges on affected ...

Dec 11, 2025
CVE-2025-13664
6.7

A privilege escalation vulnerability in Quartus Prime Standard Edition Design Software could allow local attackers to execute arbitrary code with elev...

Dec 11, 2025
CVE-2025-35972
6.7

This vulnerability in Intel MPI Library allows local attackers to escalate privileges by exploiting an uncontrolled search path (DLL hijacking). It af...

Nov 11, 2025
CVE-2025-32038
6.7

This CVE describes an uncontrolled search path vulnerability in Intel's FPGA Support Package for the oneAPI DPC++/C++ Compiler. It allows local authen...

Nov 11, 2025
CVE-2025-31931
6.7

This vulnerability in the ITT API software allows local attackers to escalate privileges by manipulating the search path. It affects systems running v...

Nov 11, 2025
CVE-2025-32001
6.7

This vulnerability in Intel Processor Identification Utility before version 8.0.43 allows local authenticated attackers to escalate privileges via DLL...

Nov 11, 2025
CVE-2025-30506
6.7

This vulnerability in Intel Driver and Support Assistant allows local attackers to escalate privileges by exploiting an uncontrolled search path (DLL ...

Nov 11, 2025
CVE-2025-31645
6.7

This CVE describes an uncontrolled search path vulnerability (DLL hijacking) in System Event Log Viewer Utility software that allows local authenticat...

Nov 11, 2025
CVE-2025-31647
6.7

This vulnerability in Intel Graphics Software allows local attackers to escalate privileges by exploiting an uncontrolled search path (DLL hijacking) ...

Nov 11, 2025
CVE-2025-30182
6.7

This vulnerability in Intel Distribution for Python installers allows local attackers to escalate privileges by manipulating the search path. It affec...

Nov 11, 2025
CVE-2025-25059
6.7

This vulnerability in Intel One Boot Flash Update software allows local authenticated attackers to escalate privileges via an uncontrolled search path...

Nov 11, 2025
CVE-2025-24842
6.7

This vulnerability in Intel System Support Utility allows local attackers to escalate privileges by manipulating the search path for DLLs or other res...

Nov 11, 2025
CVE-2025-24491
6.7

This vulnerability in Intel Killer Performance Suite allows local attackers to escalate privileges by exploiting an uncontrolled search path (DLL hija...

Nov 11, 2025
CVE-2025-20050
6.7

This vulnerability in Intel CIP software allows local attackers to escalate privileges via DLL hijacking. Attackers with authenticated access can exec...

Nov 11, 2025
CVE-2025-20065
6.7

This vulnerability in Display Virtualization for Windows OS software allows local attackers to escalate privileges by exploiting an uncontrolled searc...

Nov 11, 2025
CVE-2025-57716
6.7

This vulnerability allows a local low-privileged user on Windows systems to perform DLL hijacking attacks by placing malicious DLLs in the FortiClient...

Oct 14, 2025
CVE-2025-62185
6.7

This vulnerability allows attackers to execute arbitrary code by embedding malicious YouTube downloader executables in shared Anki decks. When users i...

Oct 7, 2025
CVE-2025-23355
6.7

This vulnerability in NVIDIA Nsight Graphics for Windows allows DLL hijacking attacks where an attacker could place a malicious DLL in a location that...

Oct 1, 2025
CVE-2025-27717
6.7

This vulnerability in Intel Graphics Driver software allows an authenticated local user to escalate privileges by manipulating the search path for DLL...

Aug 12, 2025
CVE-2025-24923
6.7

This vulnerability in Intel AI for Enterprise Retrieval-augmented Generation software allows authenticated users to escalate privileges through local ...

Aug 12, 2025
CVE-2025-26404
6.7

This vulnerability in Intel DSA software allows authenticated local users to escalate privileges by manipulating the search path. It affects systems r...

Aug 12, 2025
CVE-2025-21093
6.7

This vulnerability in Intel Driver & Support Assistant Tool allows authenticated local users to escalate privileges by manipulating the software's sea...

Aug 12, 2025
CVE-2025-20092
6.7

This vulnerability in Clock Jitter Tool software allows authenticated local users to escalate privileges by manipulating the search path. It affects u...

Aug 12, 2025
CVE-2025-20017
6.7

This vulnerability in Intel oneAPI Toolkit installers allows authenticated local users to escalate privileges by manipulating the search path. It affe...

Aug 12, 2025
CVE-2025-1729
6.7

A DLL hijacking vulnerability in TrackPoint Quick Menu software allows local attackers to execute arbitrary code with elevated privileges by placing m...

Jul 17, 2025
CVE-2025-20043
6.7

This vulnerability in Intel RealSense SDK allows authenticated local users to escalate privileges by manipulating the DLL search path. It affects syst...

May 13, 2025
CVE-2024-46895
6.7

This vulnerability in Intel Arc and Iris Xe graphics software allows an authenticated attacker to escalate privileges via local access by exploiting a...

May 13, 2025
CVE-2024-47795
6.7

This vulnerability in Intel oneAPI DPC++/C++ Compiler software allows authenticated local users to escalate privileges by manipulating the DLL search ...

May 13, 2025
CVE-2024-39833
6.7

This vulnerability in Intel QAT software allows authenticated local users to escalate privileges by manipulating the search path for DLL files. It aff...

May 13, 2025
CVE-2024-47006
6.7

This vulnerability allows an authenticated attacker with local access to escalate privileges on Windows 10 systems by exploiting an uncontrolled searc...

Feb 12, 2025
CVE-2024-42492
6.7

This vulnerability allows a privileged user with local access to potentially escalate privileges by exploiting an uncontrolled search path element in ...

Feb 12, 2025
CVE-2024-39813
6.7

This vulnerability in EPCT software allows authenticated local users to escalate privileges by manipulating the search path. It affects systems runnin...

Feb 12, 2025
CVE-2024-39365
6.7

This vulnerability allows an authenticated attacker with local access to escalate privileges on Windows systems by exploiting an uncontrolled search p...

Feb 12, 2025
CVE-2024-36283
6.7

This vulnerability in Intel Thread Director Visualizer software allows authenticated local users to escalate privileges by manipulating the software's...

Feb 12, 2025
CVE-2024-36291
6.7

This vulnerability in Intel Chipset Software Installation Utility allows authenticated local users to escalate privileges by manipulating the search p...

Feb 12, 2025
CVE-2024-32938
6.7

This vulnerability in Intel MPI Library for Windows allows authenticated local users to escalate privileges by manipulating the DLL search path. Attac...

Feb 12, 2025
CVE-2024-29223
6.7

This vulnerability in Intel QuickAssist Technology software allows authenticated local users to escalate privileges by manipulating the search path fo...

Feb 12, 2025
CVE-2024-21830
6.7

This vulnerability in Intel VPL software allows authenticated local users to escalate privileges by manipulating the search path for DLLs or other fil...

Feb 12, 2025
CVE-2024-24852
6.7

This vulnerability in Intel Ethernet Adapter drivers allows authenticated local users to escalate privileges by manipulating the DLL search path durin...

Feb 12, 2025
CVE-2024-53977
6.7

This vulnerability allows authenticated local attackers to execute arbitrary code with elevated privileges by exploiting a script that loads executabl...

Feb 11, 2025
CVE-2024-38387
6.7

This vulnerability in Intel Graphics Driver installers allows authenticated local users to escalate privileges by exploiting an uncontrolled search pa...

Nov 13, 2024
CVE-2024-37024
6.7

This vulnerability in Intel ACAT software for Windows allows authenticated local users to escalate privileges by manipulating the DLL search path. Att...

Nov 13, 2024
CVE-2024-35245
6.7

This vulnerability in Intel PROSet/Wireless WiFi software allows authenticated local users to escalate privileges by exploiting an uncontrolled search...

Nov 13, 2024
CVE-2024-36253
6.7

This vulnerability in Intel SDP Tool for Windows allows authenticated local users to escalate privileges by manipulating the software's search path. A...

Nov 13, 2024

About CWE-427 (CWE-427)

Our database tracks 401 CVEs classified as CWE-427, with 7 rated critical and 286 rated high severity. The average CVSS score for CWE-427 vulnerabilities is 7.5.

External reference: View CWE-427 on MITRE CWE →

Monitor CWE-427 Vulnerabilities

Get alerted when new CWE-427 CVEs affect your infrastructure.

Start Monitoring Free