CWE-428— Unquoted Search Path or Element
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.— MITRE CWE catalog
462 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-428page 9 of 10
- CVE-2024-31804MEDIUMCVSS 6.7EG 6.72024-04-23
An unquoted service path vulnerability in Terratec DMX_6Fire USB v.1.23.0.02 allows a local attacker to escalate privileges via the Program.exe component.
- CVE-2023-24542MEDIUMCVSS 6.7EG 6.72024-02-14
Unquoted search path or element in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-32658MEDIUMCVSS 6.7EG 6.72023-11-14
Unquoted search path in some Intel(R) NUC Kits NUC7i3DN, NUC7i5DN, NUC7i7DN HDMI firmware update tool software before version 1.79.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-29165MEDIUMCVSS 6.7EG 6.72023-11-14
Unquoted search path or element in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-25075MEDIUMCVSS 6.7EG 6.72023-11-14
Unquoted search path in the installer for some Intel Server Configuration Utility software before version 16.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-0392MEDIUMCVSS 6.7EG 6.72023-11-08
The LDAP Agent Update service with versions prior to 5.18 used an unquoted path, which could allow arbitrary code execution.
- CVE-2021-26735MEDIUMCVSS 6.7EG 6.72023-10-23
The Zscaler Client Connector Installer and Unsintallers for Windows prior to 3.6 had an unquoted search path vulnerability. A local adversary may be able to execute code with SYSTEM privileges.
- CVE-2023-22841MEDIUMCVSS 6.7EG 6.72023-08-11
Unquoted search path in the software installer for the System Firmware Update Utility (SysFwUpdt) for some Intel(R) Server Boards and Intel(R) Server Systems Based on Intel(R) 621A Chipset before version 16.0.7 may allow an authenticated u…
- CVE-2022-0357MEDIUMCVSS 6.7EG 6.72023-05-24
Unquoted Search Path or Element vulnerability in the Vulnerability Scan component of Bitdefender Total Security, Bitdefender Internet Security, and Bitdefender Antivirus Plus allows an attacker to elevate privileges to SYSTEM. This issue …
- CVE-2023-27386MEDIUMCVSS 6.7EG 6.72023-05-10
Uncontrolled search path in some Intel(R) Pathfinder for RISC-V software may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-43474MEDIUMCVSS 6.7EG 6.72023-05-10
Uncontrolled search path for the DSP Builder software installer before version 22.4 for Intel(R) FPGAs Pro Edition may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-41693MEDIUMCVSS 6.7EG 6.72023-05-10
Uncontrolled search path in the Intel(R) Quartus(R) Prime Pro edition software before version 22.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-38101MEDIUMCVSS 6.7EG 6.72023-05-10
Uncontrolled search path in some Intel(R) NUC Chaco Canyon BIOS update software before version iFlashV Windows 5.13.00.2105 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-34848MEDIUMCVSS 6.7EG 6.72023-05-10
Uncontrolled search path for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-36631MEDIUMCVSS 6.7EG 6.72022-12-22
Untrusted search path vulnerability in Baidunetdisk Version 7.4.3 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
- CVE-2022-46662MEDIUMCVSS 6.7EG 6.72022-12-21
Roxio Creator LJB starts another program with an unquoted file path. Since a registered Windows service path contains spaces and are unquoted, if a malicious executable is placed on a certain path, the executable may be executed with the p…
- CVE-2022-27094MEDIUMCVSS 6.7EG 6.72022-05-20
Sony PlayMemories Home v6.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.
- CVE-2021-29218MEDIUMCVSS 6.7EG 6.72022-02-04
A local unquoted search path security vulnerability has been identified in HPE Agentless Management Service for Windows version(s): Prior to 1.44.0.0, 10.96.0.0. This vulnerability could be exploited locally by a user with high privileges …
- CVE-2021-35231MEDIUMCVSS 6.7EG 6.72021-10-25
As a result of an unquoted service path vulnerability present in the Kiwi Syslog Server Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or uninstall ent…
- CVE-2021-35056MEDIUMCVSS 6.7EG 6.72021-07-15
Unisys Stealth 5.1 before 5.1.025.0 and 6.0 before 6.0.055.0 has an unquoted Windows search path for a scheduled task. An unintended executable might run.
- CVE-2021-23879MEDIUMCVSS 6.7EG 6.72021-03-15
Unquoted service path vulnerability in McAfee Endpoint Product Removal (EPR) Tool prior to 21.2 allows local administrators to execute arbitrary code, with higher-level privileges, via execution from a compromised folder. The tool did not …
- CVE-2020-7581MEDIUMCVSS 6.7EG 6.72020-07-14
A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcenter Intelligence (All versions < V3.3), O…
- CVE-2020-7580MEDIUMCVSS 6.7EG 6.72020-06-10
A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC Software V16 (All versions <…
- CVE-2020-8337MEDIUMCVSS 6.7EG 6.72020-06-09
An unquoted search path vulnerability was reported in versions prior to 1.0.83.0 of the Synaptics Smart Audio UWP app associated with the DCHU audio drivers on Lenovo platforms that could allow an administrative user to execute arbitrary c…
- CVE-2019-6145MEDIUMCVSS 6.7EG 6.72019-09-20
Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability. This enables local privilege escalation to SYSTEM user. By default, only local administrators can write executables to the vulnerable d…
- CVE-2019-11093MEDIUMCVSS 6.7EG 6.72019-05-17
Unquoted service path in the installer for the Intel(R) SCS Discovery Utility version 12.0.0.129 and earlier may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2019-6149MEDIUMCVSS 6.7EG 6.72019-03-18
An unquoted search path vulnerability was identified in Lenovo Dynamic Power Reduction Utility prior to version 2.2.2.0 that could allow a malicious user with local access to execute code with administrative privileges.
- CVE-2018-14789MEDIUMCVSS 6.7EG 6.72018-08-22
In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 3.1 or prior and Xcelera Version 4.1 or prior), an unquoted search path or element vulnerability has been identified, which may allow an attacker to execute arbitrary co…
- CVE-2017-14019MEDIUMCVSS 6.7EG 6.72017-10-19
An Unquoted Search Path or Element issue was discovered in Progea Movicon Version 11.5.1181 and prior. An unquoted search path or element vulnerability has been identified, which may allow an authorized local user to insert arbitrary code …
- CVE-2017-5873MEDIUMCVSS 6.7EG 6.72017-04-11
Unquoted Windows search path vulnerability in the guest service in Unisys s-Par before 4.4.20 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe.
- CVE-2025-24831MEDIUMCVSS 6.6EG 6.62025-01-31
Local privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.
- CVE-2020-7316MEDIUMCVSS 6.6EG 6.62020-10-07
Unquoted service path vulnerability in McAfee File and Removable Media Protection (FRP) prior to 5.3.0 allows local users to execute arbitrary code, with higher privileges, via execution and from a compromised folder. This issue may result…
- CVE-2024-31201MEDIUMCVSS 6.5EG 6.52024-07-31
A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service. Such misconfiguration could be abused in scenarios where incorrect permissions were assigned to the C:\ path to attempt a privilege escalation on…
- CVE-2022-27966MEDIUMCVSS 6.5EG 6.52022-03-31
Xshell v7.0.0099 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.
- CVE-2022-27965MEDIUMCVSS 6.5EG 6.52022-03-31
Xlpd v7.0.0094 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.
- CVE-2022-27964MEDIUMCVSS 6.5EG 6.52022-03-31
Xmanager v7.0.0096 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.
- CVE-2022-27963MEDIUMCVSS 6.5EG 6.52022-03-31
Xftp 7.0.0088p and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.
- CVE-2021-31553MEDIUMCVSS 6.5EG 6.52021-04-22
An issue was discovered in the CheckUser extension for MediaWiki through 1.35.2. MediaWiki usernames with trailing whitespace could be stored in the cu_log database table such that denial of service occurred for certain CheckUser extension…
- CVE-2023-53954MEDIUMCVSS 6.2EG 6.22025-12-19
ActFax 10.10 contains an unquoted service path vulnerability that allows local attackers to potentially escalate privileges by exploiting the ActiveFaxServiceNT service configuration. Attackers with write permissions to Program Files direc…
- CVE-2023-53912MEDIUMCVSS 6.2EG 6.22025-12-17
USB Flash Drives Control 4.1.0.0 contains an unquoted service path vulnerability in its service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\U…
- CVE-2014-0759MEDIUMCVSS 5.9EG 5.92014-02-28
Unquoted Windows search path vulnerability in Schneider Electric Floating License Manager 1.0.0 through 1.4.0 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that …
- CVE-2021-21292MEDIUMCVSS 5.5EG 5.52021-02-02
Traccar is an open source GPS tracking system. In Traccar before version 4.12 there is an unquoted Windows binary path vulnerability. Only Windows versions are impacted. Attacker needs write access to the filesystem on the host machine. If…
- CVE-2025-39246MEDIUMCVSS 5.3EG 5.32025-08-29
There is an Unquoted Service Path Vulnerability in some HikCentral FocSign versions. This could allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-2644MEDIUMCVSS 5.3EG 5.32023-05-11
A vulnerability, which was classified as problematic, has been found in DigitalPersona FPSensor 1.0.0.1. This issue affects some unknown processing of the file C:\Program Files (x86)\FPSensor\bin\DpHost.exe. The manipulation leads to unquo…
- CVE-2023-2417MEDIUMCVSS 5.3EG 5.32023-04-29
A vulnerability was found in ks-soft Advanced Host Monitor up to 12.56 and classified as problematic. Affected by this issue is some unknown functionality of the file C:\Program Files (x86)\HostMonitor\RMA-Win\rma_active.exe. The manipulat…
- CVE-2022-4429MEDIUMCVSS 5.3EG 5.32023-01-10
Avira Security for Windows contains an unquoted service path which allows attackers with local administrative privileges to cause a Denial of Service. The issue was fixed with Avira Security version 1.1.78
- CVE-2020-5147MEDIUMCVSS 5.3EG 5.32021-01-09
SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated privileges in the host operating system. This vulnerability impact SonicWall NetExtender Windows client v…
- CVE-2018-2406MEDIUMCVSS 5.3EG 5.32018-04-10
Unquoted windows search path (directory/path traversal) vulnerability in Crystal Reports Server, OEM Edition (CRSE), 4.0, 4.10, 4.20, 4.30, startup path.
- CVE-2014-5455MEDIUMCVSS 5.3EG 5.32014-08-25
Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and OpenVPN Connect version 3.1 (Windows) allows local users to gain privileges via a crafted program.exe file in the %SYSTEMD…
- CVE-2025-1984MEDIUMCVSS 5.2EG 5.22025-03-12
Xerox Desktop Print Experience application contains a Local Privilege Escalation (LPE) vulnerability, which allows a low-privileged user to gain SYSTEM-level access.
Map vulnerabilities like CWE-428 to your infrastructure
EchelonGraph correlates every CVE — across CWE-428 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →