CWE-428— Unquoted Search Path or Element
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.— MITRE CWE catalog
462 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-428page 5 of 10
- CVE-2021-47829HIGHCVSS 7.8EG 7.82026-01-16
DHCP Broadband 4.1.0.1503 contains an unquoted service path vulnerability in its service configuration that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path in 'C:\Program Files\DHCP …
- CVE-2021-47828HIGHCVSS 7.8EG 7.82026-01-16
BOOTP Turbo 2.0.0.1253 contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path to execute arbitrary code with elevated LocalSystem privileges during system startup or re…
- CVE-2021-47826HIGHCVSS 7.8EG 7.82026-01-16
Acer Backup Manager 3.0.0.99 contains an unquoted service path vulnerability in the NTI IScheduleSvc service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\N…
- CVE-2021-47825HIGHCVSS 7.8EG 7.82026-01-16
Acer Updater Service 1.2.3500.0 contains an unquoted service path vulnerability that allows local users to execute code with elevated system privileges. Attackers can exploit the unquoted path in C:\Program Files\Acer\Acer Updater\ to inje…
- CVE-2021-47823HIGHCVSS 7.8EG 7.82026-01-16
Acer ePowerSvc 6.0.3008.0 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject m…
- CVE-2021-47822HIGHCVSS 7.8EG 7.82026-01-16
DiskBoss Service 12.2.18 contains an unquoted service path vulnerability in its binary path configuration that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path by placing malicious ex…
- CVE-2021-47810HIGHCVSS 7.8EG 7.82026-01-16
WibuKey Runtime 6.51 contains an unquoted service path vulnerability in the WkSvW32.exe service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\PROGRAM FILES (X86)\WIBUKEY\S…
- CVE-2021-47809HIGHCVSS 7.8EG 7.82026-01-16
Disk Sorter Enterprise 13.6.12 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program F…
- CVE-2021-47807HIGHCVSS 7.8EG 7.82026-01-16
Sync Breeze 13.6.18 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in service binaries located…
- CVE-2021-47806HIGHCVSS 7.8EG 7.82026-01-16
Dup Scout 13.5.28 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Dup Scou…
- CVE-2021-47805HIGHCVSS 7.8EG 7.82026-01-16
Disk Savvy 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in service binaries to injec…
- CVE-2021-47804HIGHCVSS 7.8EG 7.82026-01-16
Wise Care 365 5.6.7.568 contains an unquoted service path vulnerability in the WiseBootAssistant service running with LocalSystem privileges. Attackers can exploit this by inserting a malicious executable in the service path, which will ex…
- CVE-2021-47803HIGHCVSS 7.8EG 7.82026-01-16
iFunbox 4.2 contains an unquoted service path vulnerability in the Apple Mobile Device Service that allows local attackers to execute code with elevated privileges. Attackers can insert a malicious executable into the unquoted service path…
- CVE-2021-47792HIGHCVSS 7.8EG 7.82026-01-16
Remote Mouse 4.002 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the RemoteMouseService to inject m…
- CVE-2021-47790HIGHCVSS 7.8EG 7.82026-01-16
Active WebCam 11.5 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the misconfigured service path by placing malicious executables…
- CVE-2021-47787HIGHCVSS 7.8EG 7.82026-01-16
TotalAV 5.15.69 contains an unquoted service path vulnerability in multiple system services running with LocalSystem privileges. Attackers can place malicious executables in specific unquoted path segments to potentially gain SYSTEM-level …
- CVE-2021-47780HIGHCVSS 7.8EG 7.82026-01-16
Macro Expert 4.7 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the improperly configured service path to inject maliciou…
- CVE-2020-36930HIGHCVSS 7.8EG 7.82026-01-16
SysGauge Server 7.9.18 contains an unquoted service path vulnerability in its binary path configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\SysGaug…
- CVE-2020-36929HIGHCVSS 7.8EG 7.82026-01-16
Brother BRPrint Auditor 3.0.7 contains an unquoted service path vulnerability in its Windows service configurations that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted file paths in BrAuSvc…
- CVE-2020-36928HIGHCVSS 7.8EG 7.82026-01-16
Brother BRAgent 1.38 contains an unquoted service path vulnerability in the WBA_Agent_Client service running with LocalSystem privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Brother\BRAgent\ to inject and exec…
- CVE-2020-36927HIGHCVSS 7.8EG 7.82026-01-16
DiskPulse Enterprise 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Fil…
- CVE-2021-47773HIGHCVSS 7.8EG 7.82026-01-15
Dynojet Power Core 2.3.0 contains an unquoted service path vulnerability in the DJ.UpdateService that allows local authenticated users to potentially execute code with elevated privileges. Attackers can exploit the unquoted binary path by …
- CVE-2021-47767HIGHCVSS 7.8EG 7.82026-01-15
10-Strike Network Inventory Explorer Pro 9.31 contains an unquoted service path vulnerability in the srvInventoryWebServer service running with LocalSystem privileges. Attackers can exploit the unquoted path by placing malicious executable…
- CVE-2021-47762HIGHCVSS 7.8EG 7.82026-01-15
HTTPDebuggerPro 9.11 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configura…
- CVE-2025-66575HIGHCVSS 7.8EG 7.82025-12-04
VeeVPN 1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute code during startup or reboot with escalated privileges. Attackers can exploit this by providing a malicious service n…
- CVE-2025-57227HIGHCVSS 7.8EG 7.82025-10-29
An unquoted service path in Kingosoft Technology Ltd Kingo ROOT v1.5.8.3353 allows attackers to escalate privileges via placing a crafted executable file into a parent folder.
- CVE-2025-57714HIGHCVSS 7.8EG 7.82025-10-03
An unquoted search path or element vulnerability has been reported to affect NetBak Replicator. If a local attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fi…
- CVE-2025-43993HIGHCVSS 7.8EG 7.82025-09-25
Dell Wireless 5932e and Qualcomm Snapdragon X62 Firmware and GNSS/GPS Driver, versions prior to 3.2.0.22 contain an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could potentially exploit this v…
- CVE-2025-10199HIGHCVSS 7.8EG 7.82025-09-09
A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely prior versions) due to an unquoted service path.
- CVE-2025-21107HIGHCVSS 7.8EG 7.82025-01-30
Dell NetWorker, version(s) prior to 19.11.0.3, all versions of 19.10 & prior versions contain(s) an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, le…
- CVE-2024-9287HIGHCVSS 7.8EG 7.82024-10-22
A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scrip…
- CVE-2024-9325HIGHCVSS 7.8EG 7.82024-09-29
A vulnerability classified as critical has been found in Intelbras InControl up to 2.21.56. This affects an unknown part of the file C:\Program Files (x86)\Intelbras\Incontrol Cliente\incontrol_webcam\incontrol-service-watchdog.exe. The ma…
- CVE-2024-43457HIGHCVSS 7.8EG 7.82024-09-10
Windows Setup and Deployment Elevation of Privilege Vulnerability
- CVE-2024-5402HIGHCVSS 7.8EG 7.82024-07-15
Unquoted Search Path or Element vulnerability in ABB Mint Workbench. A local attacker who successfully exploited this vulnerability could gain elevated privileges by inserting an executable file in the path of the affected service. Th…
- CVE-2024-6080HIGHCVSS 7.8EG 7.82024-06-17
A vulnerability classified as critical was found in Intelbras InControl 2.21.56. This vulnerability affects unknown code of the component incontrolWebcam Service. The manipulation leads to unquoted search path. Local access is required to …
- CVE-2024-2747HIGHCVSS 7.8EG 7.82024-06-12
CWE-428: Unquoted search path or element vulnerability exists in Easergy Studio, which could cause privilege escalation when a valid user replaces a trusted file name on the system and reboots the machine.
- CVE-2024-4461HIGHCVSS 7.8EG 7.82024-05-03
Unquoted path or search item vulnerability in SugarSync versions prior to 4.1.3 for Windows. This misconfiguration could allow an unauthorized local user to inject arbitrary code into the unquoted service path, resulting in privilege escal…
- CVE-2024-1618HIGHCVSS 7.8EG 7.82024-03-12
A search path or unquoted item vulnerability in Faronics Deep Freeze Server Standard, which affects versions 8.30.020.4627 and earlier. This vulnerability affects the DFServ.exe file. An attacker with local user privileges could exploit t…
- CVE-2024-25552HIGHCVSS 7.8EG 7.82024-03-01
A local attacker can gain administrative privileges by inserting an executable file in the path of the affected product.
- CVE-2024-1201HIGHCVSS 7.8EG 7.82024-02-02
Search path or unquoted item vulnerability in HDD Health affecting versions 4.2.0.112 and earlier. This vulnerability could allow a local attacker to store a malicious executable file within the unquoted search path, resulting in privilege…
- CVE-2023-6631HIGHCVSS 7.8EG 7.82024-01-08
PowerSYSTEM Center versions 2020 Update 16 and prior contain a vulnerability that may allow an authorized local user to insert arbitrary code into the unquoted service path and escalate privileges.
- CVE-2023-37537HIGHCVSS 7.8EG 7.82023-10-17
An unquoted service path vulnerability in HCL AppScan Presence, deployed as a Windows service in HCL AppScan on Cloud (ASoC), may allow a local attacker to gain elevated privileges.
- CVE-2023-42486HIGHCVSS 7.8EG 7.82023-09-27
Fortect - CWE-428: Unquoted Search Path or Element, may be used by local user to elevate privileges.
- CVE-2023-5012HIGHCVSS 7.8EG 7.82023-09-16
A vulnerability, which was classified as problematic, was found in Topaz OFD 2.11.0.201. This affects an unknown part of the file C:\Program Files\Topaz OFD\Warsaw\core.exe of the component Protection Module Warsaw. The manipulation leads …
- CVE-2023-4991HIGHCVSS 7.8EG 7.82023-09-15
A vulnerability was found in NextBX QWAlerter 4.50. It has been rated as critical. Affected by this issue is some unknown functionality of the file QWAlerter.exe. The manipulation leads to unquoted search path. It is possible to launch the…
- CVE-2023-36658HIGHCVSS 7.8EG 7.82023-09-15
An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. It has an unquoted service path that can be abused locally.
- CVE-2023-26911HIGHCVSS 7.8EG 7.82023-07-26
ASUS SetupAsusServices v1.0.5.1 in Asus Armoury Crate v5.3.4.0 contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.
- CVE-2023-3842HIGHCVSS 7.8EG 7.82023-07-23
A vulnerability was found in Pointware EasyInventory 1.0.12.0 and classified as critical. This issue affects some unknown processing of the file C:\Program Files (x86)\EasyInventory\Easy2W.exe. The manipulation leads to unquoted search pat…
- CVE-2023-31747HIGHCVSS 7.8EG 7.82023-05-23
Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the component NativePushService. This vulnerability allows attackers to launch processes with elevated privileges.
- CVE-2023-2331HIGHCVSS 7.8EG 7.82023-04-27
Unquoted service Path or Element vulnerability in 42Gears Surelock Windows SureLock Service (NixService.Exe) on Windows application will allows to insert arbitrary code into the service. This issue affects Surelock Windows : from 2.3.12 th…
Map vulnerabilities like CWE-428 to your infrastructure
EchelonGraph correlates every CVE — across CWE-428 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →