CWE-428— Unquoted Search Path or Element
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.— MITRE CWE catalog
462 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-428page 8 of 10
- CVE-2024-8975HIGHCVSS 7.3EG 7.32024-09-25
Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Alloy: before 1.3.3, from 1.4.0-rc.0 through 1.4.0-rc.1.
- CVE-2024-22437HIGHCVSS 7.3EG 7.32024-04-15
A potential security vulnerability has been identified in VSS Provider and CAPI Proxy software for certain HPE MSA storage products. This vulnerability could be exploited to gain elevated privilege on the system.
- CVE-2023-22282HIGHCVSS 7.3EG 7.32023-04-11
WAB-MAT Ver.5.0.0.8 and earlier starts another program with an unquoted file path. Since a registered Windows service path contains spaces and are unquoted, if a malicious executable is placed on a certain path, the executable may be execu…
- CVE-2021-0112HIGHCVSS 7.3EG 7.32021-06-09
Unquoted service path in the Intel Unite(R) Client for Windows before version 4.2.25031 may allow an authenticated user to potentially enable an escalation of privilege via local access.
- CVE-2020-8326HIGHCVSS 7.3EG 7.32020-07-24
An unquoted service path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges.
- CVE-2020-8327HIGHCVSS 7.3EG 7.32020-04-14
A privilege escalation vulnerability was reported in LenovoBatteryGaugePackage for Lenovo System Interface Foundation bundled in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authenticated user to execute code with eleva…
- CVE-2017-7180HIGHCVSS 7.3EG 7.32017-06-08
Net Monitor for Employees Pro through 5.3.4 has an unquoted service path, which allows a Security Feature Bypass of its documented "Block applications" design goal. The local attacker must have privileges to write to program.exe in a prote…
- CVE-2022-36384HIGHCVSS 6.7EG 7.32022-11-11
Unquoted search path in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2025-66264HIGHCVSS 7.2EG 7.22025-11-26
The CMService.exe service runs with SYSTEM privileges and contains an unquoted service path. This allows a local attacker with write privileges to the filesystem to insert a malicious executable in the path, leading to privilege escalation.
- CVE-2023-39464HIGHCVSS 7.2EG 7.22024-05-03
Triangle MicroWorks SCADA Data Gateway GTWWebMonitorService Unquoted Search Path Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute code on affected installations of Triangle MicroWorks SCADA Data Ga…
- CVE-2020-24682HIGHCVSS 7.2EG 7.22024-02-02
Unquoted Search Path or Element vulnerability in B&R Industrial Automation Automation Studio, B&R Industrial Automation NET/PVI allows Target Programs with Elevated Privileges.This issue affects Automation Studio: from 4.0 through 4.6, fro…
- CVE-2023-2685HIGHCVSS 7.2EG 7.22023-07-28
A vulnerability was found in AO-OPC server versions mentioned above. As the directory information for the service entry is not enclosed in quotation marks, potential attackers could possibly call up another application than the AO-OPC serv…
- CVE-2022-27905HIGHCVSS 7.2EG 7.22022-04-27
In ControlUp Real-Time Agent before 8.6, an unquoted path can result in privilege escalation. An attacker would require write permissions to the root level of the OS drive (C:\) to exploit this.
- CVE-2019-16647HIGHCVSS 7.2EG 7.22019-10-29
Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows.
- CVE-2026-77827HIGHCVSS 7.1EG 7.12026-09-08
Maono Link 3.8.13 MaonoAiServices Windows service allows local privilege escalation for a standard user account via improper write privileges in 'C:\ProgramData\Maono'. Fixed in 4.0.80.
- CVE-2025-66269HIGHCVSS 7.1EG 7.12025-11-26
The RupsMon and USBMate services in UPSilon 2000 run with SYSTEM privileges and contain unquoted service paths. This allows a local attacker to perform path interception and escalate privileges if they have write permissions to the directo…
- CVE-2026-57223HIGHCVSS 7.0EG 7.02026-09-18
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the Windows service installation and parameter-update logic in src/win32-service.c can pass an…
- CVE-2026-2542HIGHCVSS 7.0EG 7.02026-02-16
A weakness has been identified in Total VPN 0.5.29.0 on Windows. Affected by this vulnerability is an unknown functionality of the file C:\Program Files\Total VPN\win-service.exe. Executing a manipulation can lead to unquoted search path. …
- CVE-2025-13433HIGHCVSS 7.0EG 7.02025-11-20
A security flaw has been discovered in Muse Group MuseHub 2.1.0.1567. The affected element is an unknown function of the file C:\Program Files\WindowsApps\Muse.MuseHub_2.1.0.1567_x64__rb9pth70m6nz6\Muse.Updater.exe of the component Windows…
- CVE-2025-12286HIGHCVSS 7.0EG 7.02025-10-27
A weakness has been identified in VeePN up to 1.6.2. This affects an unknown function of the file C:\Program Files (x86)\VeePN\avservice\avservice.exe of the component AVService. This manipulation causes unquoted search path. The attack re…
- CVE-2025-12247HIGHCVSS 7.0EG 7.02025-10-27
A weakness has been identified in Hasleo Backup Suite up to 5.2. Impacted is an unknown function of the component HasleoImageMountService/HasleoBackupSuiteService. This manipulation causes unquoted search path. The attack is restricted to …
- CVE-2025-4540HIGHCVSS 7.0EG 7.02025-05-11
A vulnerability was found in MTSoftware C-Lodop 6.6.1.1 on Windows. It has been rated as critical. This issue affects some unknown processing of the component CLodopPrintService. The manipulation leads to unquoted search path. The attack n…
- CVE-2024-3640HIGHCVSS 7.0EG 7.02024-05-16
An unquoted executable path exists in the Rockwell Automation FactoryTalk® Remote Access™ possibly resulting in remote code execution if exploited. While running the FTRA installer package, the executable path is not properly quoted, w…
- CVE-2020-28209HIGHCVSS 7.0EG 7.02020-11-19
A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user who has write permis…
- CVE-2017-9644HIGHCVSS 7.0EG 7.02017-08-25
An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteSc…
- CVE-2025-34499MEDIUMCVSS 6.9EG 6.92025-12-11
AnyDesk 7.0.15 and 9.0.1 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated SYSTEM privileges. Attackers can exploit the unquoted service path configuration to i…
- CVE-2020-7382MEDIUMCVSS 6.8EG 6.82020-09-03
Rapid7 Nexpose installer version prior to 6.6.40 contains an Unquoted Search Path which may allow an attacker on the local machine to insert an arbitrary file into the executable path. This issue affects: Rapid7 Nexpose versions prior to 6…
- CVE-2026-66839MEDIUMCVSS 6.7EG 6.72026-08-05
NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerability (CWE-428). An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privilege…
- CVE-2026-7280MEDIUMCVSS 6.7EG 6.72026-04-28
AVACAST developed by eMPIA Technology has a Unquoted Service Path vulnerability, allowing privileged local attackers to place a malicious executable file in a specific directory, resulting in arbitrary code execution with system privileges…
- CVE-2026-33253MEDIUMCVSS 6.7EG 6.72026-03-25
SANUPS SOFTWARE provided by SANYO DENKI CO., LTD. registers Windows services with unquoted file paths. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
- CVE-2026-26033MEDIUMCVSS 6.7EG 6.72026-03-05
UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Unquoted Search Path or Element (CWE-428) vulnerability, which allows a user with write access to a directory on the system drive to execute arbitrary code with S…
- CVE-2026-1585MEDIUMCVSS 6.7EG 6.72026-02-27
An unquoted Windows service executable path vulnerability in IJ Scan Utility for Windows versions 1.1.2 through 1.5.0 may allow a local attacker to execute a malicious file with the privileges of the affected service.
- CVE-2026-24466MEDIUMCVSS 6.7EG 6.72026-02-09
Products provided by Oki Electric Industry Co., Ltd. and its OEM products (Ricoh Co., Ltd., Murata Machinery, Ltd.) register Windows services with unquoted file paths. A user with the write permission on the root directory of the system dr…
- CVE-2025-59888MEDIUMCVSS 6.7EG 6.72025-12-26
Improper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the file system. This security issue has been fixed in the latest version of EUC w…
- CVE-2025-66271MEDIUMCVSS 6.7EG 6.72025-12-09
Clone for Windows provided by ELECOM CO.,LTD. registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
- CVE-2025-66461MEDIUMCVSS 6.7EG 6.72025-12-08
FULLBACK Manager Pro provided by GS Yuasa International Ltd. registers two Windows services with unquoted file paths. A user may execute arbitrary code with SYSTEM privilege if he/she has the write permission on the path to the directory …
- CVE-2025-32449MEDIUMCVSS 6.7EG 6.72025-11-11
Unquoted search path for some PRI Driver software before version 03.03.1002 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity a…
- CVE-2025-64151MEDIUMCVSS 6.7EG 6.72025-11-05
Multiple Roboticsware products provided by Roboticsware PTE. LTD. register Windows services with unquoted file paths. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privile…
- CVE-2025-62225MEDIUMCVSS 6.7EG 6.72025-11-05
Optical Disc Archive Software provided by Sony Corporation registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
- CVE-2025-60320MEDIUMCVSS 6.7EG 6.72025-10-29
memoQ 10.1.13.ef1b2b52aae and earlier contains an unquoted service path vulnerability in the memoQ Auto Update Service (memoQauhlp101). The affected service is installed with a path containing spaces and without surrounding quotes. This mi…
- CVE-2025-61865MEDIUMCVSS 6.7EG 6.72025-10-23
Multiple NAS management applications provided by I-O DATA DEVICE, INC. register Windows services with unquoted file paths. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM pr…
- CVE-2025-61871MEDIUMCVSS 6.7EG 6.72025-10-10
NAS Navigator2 Windows version by BUFFALO INC. registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
- CVE-2025-54081MEDIUMCVSS 6.7EG 6.72025-09-23
Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineService is installed with an unquoted executable path. If Sunshine is installed in a directory whose name includes a spa…
- CVE-2025-9818MEDIUMCVSS 6.7EG 6.72025-09-17
A vulnerability (CWE-428) has been identified in the Uninterruptible Power Supply (UPS) management application provided by OMRON SOCIAL SOLUTIONS Co., Ltd., where the executable file paths of Windows services are not enclosed in quotation …
- CVE-2025-59307MEDIUMCVSS 6.7EG 6.72025-09-17
RAID Manager provided by Century Corporation registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
- CVE-2025-58400MEDIUMCVSS 6.7EG 6.72025-09-05
RATOC RAID Monitoring Manager for Windows provided by RATOC Systems, Inc. registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SY…
- CVE-2025-57699MEDIUMCVSS 6.7EG 6.72025-08-22
Western Digital Kitfox for Windows provided by Western Digital Corporation registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with …
- CVE-2025-9043MEDIUMCVSS 6.7EG 6.72025-08-14
The service executable path in Seagate Toolkit on Versions prior to 2.34.0.33 on Windows allows an attacker with Admin privileges to exploit a vulnerability as classified under CWE-428: Unquoted Search Path or Element. An attacker with wri…
- CVE-2022-27592MEDIUMCVSS 6.7EG 6.72024-09-06
An unquoted search path or element vulnerability has been reported to affect QVR Smart Client. If exploited, the vulnerability could allow local authenticated administrators to execute unauthorized code or commands via unspecified vectors.…
- CVE-2024-5963MEDIUMCVSS 6.7EG 6.72024-08-06
Unquoted Executable Path vulnerability in Hitachi Device Manager on Windows (Device Manager Server component).This issue affects Hitachi Device Manager: before 8.8.7-00.
Map vulnerabilities like CWE-428 to your infrastructure
EchelonGraph correlates every CVE — across CWE-428 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →