CWE-428— Unquoted Search Path or Element
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.— MITRE CWE catalog
462 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-428page 6 of 10
- CVE-2023-24671HIGHCVSS 7.8EG 7.82023-03-16
VX Search v13.8 and v14.7 was discovered to contain an unquoted service path vulnerability which allows attackers to execute arbitrary commands at elevated privileges via a crafted executable file.
- CVE-2023-24575HIGHCVSS 7.8EG 7.82023-02-21
Dell Multifunction Printer E525w Driver and Software Suite, versions prior to 1.047.2022, A05, contain a local privilege escalation vulnerability that could be exploited by malicious users to compromise the affected system
- CVE-2022-44264HIGHCVSS 7.8EG 7.82023-01-26
Dentsply Sirona Sidexis <= 4.3 is vulnerable to Unquoted Service Path.
- CVE-2022-4258HIGHCVSS 7.8EG 7.82023-01-16
In multiple versions of HIMA PC based Software an unquoted Windows search path vulnerability might allow local users to gain privileges via a malicious .exe file and gain full access to the system.
- CVE-2019-19705HIGHCVSS 7.8EG 7.82022-12-26
Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG before 6.0.8907.1 (and on many other Lenovo and non-Lenovo products), mishandles DLL preloading.
- CVE-2022-37197HIGHCVSS 7.8EG 7.82022-11-18
IOBit IOTransfer V4 is vulnerable to Unquoted Service Path.
- CVE-2021-3305HIGHCVSS 7.8EG 7.82022-10-18
Beijing Feishu Technology Co., Ltd Feishu v3.40.3 was discovered to contain an untrusted search path vulnerability.
- CVE-2022-33920HIGHCVSS 7.8EG 7.82022-10-12
Dell GeoDrive, versions prior to 2.2, contains an Unquoted File Path vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to the execution of arbitrary code in the SYSTEM security context.
- CVE-2022-39959HIGHCVSS 7.8EG 7.82022-10-07
Panini Everest Engine 2.0.4 allows unprivileged users to create a file named Everest.exe in the %PROGRAMDATA%\Panini folder. This leads to privilege escalation because a service, running as SYSTEM, uses the unquoted path of %PROGRAMDATA%\P…
- CVE-2022-35292HIGHCVSS 7.8EG 7.82022-09-13
In SAP Business One application when a service is created, the executable path contains spaces and isn’t enclosed within quotes, leading to a vulnerability known as Unquoted Service Path which allows a user to gain SYSTEM privileges. If …
- CVE-2022-35899HIGHCVSS 7.8EG 7.82022-07-21
There is an unquoted service path in ASUSTeK Aura Ready Game SDK service (GameSDK.exe) 1.0.0.4. This might allow a local user to escalate privileges by creating a %PROGRAMFILES(X86)%\ASUS\GameSDK.exe file.
- CVE-2022-31591HIGHCVSS 7.8EG 7.82022-07-12
SAP BusinessObjects BW Publisher Service - versions 420, 430, uses a search path that contains an unquoted element. A local attacker can gain elevated privileges by inserting an executable file in the path of the affected service
- CVE-2022-31590HIGHCVSS 7.8EG 7.82022-06-14
SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to work around system’s root disk access restrictions to Write/Create a program file on system disk root path, which co…
- CVE-2022-29320HIGHCVSS 7.8EG 7.82022-05-20
MiniTool Partition Wizard v12.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.
- CVE-2022-27095HIGHCVSS 7.8EG 7.82022-05-20
BattlEye v0.9 contains an unquoted service path which allows attackers to escalate privileges to the system level.
- CVE-2022-26634HIGHCVSS 7.8EG 7.82022-05-20
HMA VPN v5.3.5913.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.
- CVE-2022-27089HIGHCVSS 7.8EG 7.82022-04-11
In Fujitsu PlugFree Network <= 7.3.0.3, an Unquoted service path in PFNService.exe software allows a local attacker to potentially escalate privileges to system level.
- CVE-2022-27088HIGHCVSS 7.8EG 7.82022-04-11
Ivanti DSM Remote <= 6.3.1.1862 is vulnerable to an unquoted service path allowing local users to launch processes with elevated privileges.
- CVE-2022-23909HIGHCVSS 7.8EG 7.82022-04-05
There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might allow a local user to escalate privileges by creating a "C:\Program Files\Sherpa Software\Sherpa.exe" file.
- CVE-2021-43463HIGHCVSS 7.8EG 7.82022-04-04
An Unquoted Service Path vulnerability exists in Ext2Fsd v0.68 via a specially crafted file in the Ext2Srv Service executable service path.
- CVE-2021-43460HIGHCVSS 7.8EG 7.82022-04-04
An Unquoted Service Path vulnerability exists in System Explorer 7.0.0 via via a specially crafted file in the SystemExplorerHelpService service executable path.
- CVE-2021-43458HIGHCVSS 7.8EG 7.82022-04-04
An Unquoted Service Path vulnerability exits in Vembu BDR 4.2.0.1 via a specially crafted file in the (1) hsflowd, (2) VembuBDR360Agent, or (3) VembuOffice365Agent service paths.
- CVE-2021-43457HIGHCVSS 7.8EG 7.82022-04-04
An Unquoted Service Path vulnerability exists in bVPN 2.5.1 via a specially crafted file in the waselvpnserv service path.
- CVE-2021-43456HIGHCVSS 7.8EG 7.82022-04-04
An Unquoted Service Path vulnerablility exists in Rumble Mail Server 0.51.3135 via via a specially crafted file in the RumbleService executable service path.
- CVE-2021-43455HIGHCVSS 7.8EG 7.82022-04-04
An Unquoted Service Path vulnerability exists in FreeLAN 2.2 via a specially crafted file in the FreeLAN Service path.
- CVE-2021-43454HIGHCVSS 7.8EG 7.82022-04-04
An Unquoted Service Path vulnerability exists in AnyTXT Searcher 1.2.394 via a specially crafted file in the ATService path. .
- CVE-2022-27052HIGHCVSS 7.8EG 7.82022-03-31
FreeFtpd version 1.0.13 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.
- CVE-2022-27050HIGHCVSS 7.8EG 7.82022-03-31
BitComet Service for Windows before version 1.8.6 contains an unquoted service path vulnerability which allows attackers to escalate privileges to the system level.
- CVE-2022-25031HIGHCVSS 7.8EG 7.82022-03-03
Remote Desktop Commander Suite Agent before v4.8 contains an unquoted service path which allows attackers to escalate privileges to the system level.
- CVE-2021-46368HIGHCVSS 7.8EG 7.82022-02-17
TRIGONE Remote System Monitor 3.61 is vulnerable to an unquoted path service allowing local users to launch processes with elevated privileges.
- CVE-2021-33095HIGHCVSS 7.8EG 7.82021-11-17
Unquoted search path in the installer for the Intel(R) NUC M15 Laptop Kit Keyboard LED Service driver pack before version 1.0.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-42563HIGHCVSS 7.8EG 7.82021-11-12
There is an Unquoted Service Path in NI Service Locator (nisvcloc.exe) in versions prior to 18.0 on Windows. This may allow an authorized local user to insert arbitrary code into the unquoted service path and escalate privileges.
- CVE-2021-40683HIGHCVSS 7.8EG 7.82021-10-04
In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquoted path may allow an attacker to hijack the flow of execution.
- CVE-2020-11632HIGHCVSS 7.8EG 7.82021-07-15
The Zscaler Client Connector prior to 2.1.2.150 did not quote the search path for services, which allows a local adversary to execute code with system privileges.
- CVE-2021-35469HIGHCVSS 7.8EG 7.82021-07-14
The Lexmark Printer Software G2, G3 and G4 Installation Packages have a local escalation of privilege vulnerability due to a registry entry that has an unquoted service path.
- CVE-2020-22809HIGHCVSS 7.8EG 7.82021-05-10
In Windscribe v1.83 Build 20, 'WindscribeService' has an Unquoted Service Path that facilitates privilege escalation.
- CVE-2021-31776HIGHCVSS 7.8EG 7.82021-04-29
Aviatrix VPN Client before 2.14.14 on Windows has an unquoted search path that enables local privilege escalation to the SYSTEM user, if the machine is misconfigured to allow unprivileged users to write to directories that are supposed to …
- CVE-2020-7331HIGHCVSS 7.8EG 7.82020-11-12
Unquoted service executable path in McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows local users to cause a denial of service and malicious file execution via carefully crafted and named executable files.
- CVE-2020-27992HIGHCVSS 7.8EG 7.82020-11-02
Dr.Fone 3.0.0 allows local users to gain privileges via a Trojan horse DriverInstall.exe because %PROGRAMFILES(X86)%\Wondershare\dr.fone\Library\DriverInstaller has Full Control for BUILTIN\Users.
- CVE-2020-10051HIGHCVSS 7.8EG 7.82020-09-09
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). Multiple services of the affected application are executed with SYSTEM privileges while the call path is not quoted. This could allow a local at…
- CVE-2020-0546HIGHCVSS 7.8EG 7.82020-03-12
Unquoted service path in Intel(R) Optane(TM) DC Persistent Memory Module Management Software before version 1.0.0.3461 may allow an authenticated user to potentially enable escalation of privilege and denial of service via local access.
- CVE-2019-18915HIGHCVSS 7.8EG 7.82020-02-13
A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version 1.4.33. This vulnerability may allow a local attacker to execute arbitrary code via an HP System Event Utility system …
- CVE-2019-20357HIGHCVSS 7.8EG 7.82020-01-18
A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate p…
- CVE-2019-20362HIGHCVSS 7.8EG 7.82020-01-08
In Teradici PCoIP Agent before 19.08.1 and PCoIP Client before 19.08.3, an unquoted service path can cause execution of %PROGRAMFILES(X86)%\Teradici\PCoIP.exe instead of the intended pcoip_vchan_printing_svc.exe file.
- CVE-2019-6008HIGHCVSS 7.8EG 7.82019-12-26
An unquoted search path vulnerability in Multiple Yokogawa products for Windows (Exaopc (R1.01.00 ? R3.77.00), Exaplog (R1.10.00 ? R3.40.00), Exaquantum (R1.10.00 ? R3.02.00 and R3.15.00), Exaquantum/Batch (R1.01.00 ? R2.50.40), Exasmoc (a…
- CVE-2019-7487HIGHCVSS 7.8EG 7.82019-12-19
Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not put the path in quotes, so if a malicious binary by an attacker within the parent path could allow code execution.
- CVE-2019-18245HIGHCVSS 7.8EG 7.82019-12-11
Reliable Controls LicenseManager versions 3.4 and prior may allow an authenticated user to insert malicious code into the system root path, which may allow execution of code with elevated privileges of the application.
- CVE-2019-7201HIGHCVSS 7.8EG 7.82019-12-04
An unquoted service path vulnerability is reported to affect the service QVssService in QNAP NetBak Replicator. This vulnerability could allow an authorized but non-privileged local user to execute arbitrary code with elevated system privi…
- CVE-2019-14685HIGHCVSS 7.8EG 7.82019-08-21
A local privilege escalation vulnerability exists in Trend Micro Security 2019 (v15.0) in which, if exploited, would allow an attacker to manipulate a specific product feature to load a malicious service.
- CVE-2018-20341HIGHCVSS 7.8EG 7.82019-04-08
WINMAGIC SecureDoc Disk Encryption software before 8.3 has an Unquoted Service Path vulnerability, which could allow an attacker to execute arbitrary code on a target system. If the executable is enclosed in quote tags "" then the system w…
Map vulnerabilities like CWE-428 to your infrastructure
EchelonGraph correlates every CVE — across CWE-428 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →