VYPR

CWE-428

Unquoted Search Path or Element

BaseDraft

Description

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

If a malicious individual has access to the file system, it is possible to elevate privileges by inserting such a file as "C:\Program.exe" to be run by a privileged program making use of WinExec.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (454)

page 11 of 23
  • CVE-2021-47807HigJan 16, 2026
    risk 0.51cvss 7.8epss 0.00

    Sync Breeze 13.6.18 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in service binaries located in 'Program Files' directories to…

  • CVE-2021-47806HigJan 16, 2026
    risk 0.51cvss 7.8epss 0.00

    Dup Scout 13.5.28 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Dup Scout Server\bin\dupscts.exe' to inject…

  • CVE-2021-47805HigJan 16, 2026
    risk 0.51cvss 7.8epss 0.00

    Disk Savvy 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in service binaries to inject malicious executables that will be run…

  • CVE-2021-47804HigJan 16, 2026
    risk 0.51cvss 7.8epss 0.00

    Wise Care 365 5.6.7.568 contains an unquoted service path vulnerability in the WiseBootAssistant service running with LocalSystem privileges. Attackers can exploit this by inserting a malicious executable in the service path, which will execute with elevated system privileges…

  • CVE-2021-47803HigJan 16, 2026
    risk 0.51cvss 7.8epss 0.00

    iFunbox 4.2 contains an unquoted service path vulnerability in the Apple Mobile Device Service that allows local attackers to execute code with elevated privileges. Attackers can insert a malicious executable into the unquoted service path to run with LocalSystem privileges when…

  • CVE-2021-47792HigJan 16, 2026
    risk 0.51cvss 7.8epss 0.00

    Remote Mouse 4.002 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the RemoteMouseService to inject malicious executables and gain…

  • CVE-2021-47790HigJan 16, 2026
    risk 0.51cvss 7.8epss 0.00

    Active WebCam 11.5 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the misconfigured service path by placing malicious executables in specific directory locations to gain…

  • CVE-2021-47787HigJan 16, 2026
    risk 0.51cvss 7.8epss 0.00

    TotalAV 5.15.69 contains an unquoted service path vulnerability in multiple system services running with LocalSystem privileges. Attackers can place malicious executables in specific unquoted path segments to potentially gain SYSTEM-level access by exploiting the service path…

  • CVE-2021-47780HigJan 16, 2026
    risk 0.51cvss 7.8epss 0.00

    Macro Expert 4.7 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the improperly configured service path to inject malicious executables that will be run with…

  • CVE-2020-36930HigJan 16, 2026
    risk 0.51cvss 7.8epss 0.00

    SysGauge Server 7.9.18 contains an unquoted service path vulnerability in its binary path configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\SysGauge Server\bin\sysgaus.exe' to inject…

  • CVE-2020-36929HigJan 16, 2026
    risk 0.51cvss 7.8epss 0.00

    Brother BRPrint Auditor 3.0.7 contains an unquoted service path vulnerability in its Windows service configurations that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted file paths in BrAuSvc and BRPA_Agent services to inject…

  • CVE-2020-36928HigJan 16, 2026
    risk 0.51cvss 7.8epss 0.00

    Brother BRAgent 1.38 contains an unquoted service path vulnerability in the WBA_Agent_Client service running with LocalSystem privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Brother\BRAgent\ to inject and execute malicious code with elevated system…

  • CVE-2020-36927HigJan 16, 2026
    risk 0.51cvss 7.8epss 0.00

    DiskPulse Enterprise 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Disk Pulse…

  • CVE-2021-47773HigJan 15, 2026
    risk 0.51cvss 7.8epss 0.00

    Dynojet Power Core 2.3.0 contains an unquoted service path vulnerability in the DJ.UpdateService that allows local authenticated users to potentially execute code with elevated privileges. Attackers can exploit the unquoted binary path by placing malicious executables in the…

  • CVE-2021-47767HigJan 15, 2026
    risk 0.51cvss 7.8epss 0.00

    10-Strike Network Inventory Explorer Pro 9.31 contains an unquoted service path vulnerability in the srvInventoryWebServer service running with LocalSystem privileges. Attackers can exploit the unquoted path by placing malicious executables in potential path segments to achieve…

  • CVE-2021-47762HigJan 15, 2026
    risk 0.51cvss 7.8epss 0.00

    HTTPDebuggerPro 9.11 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables and…

  • CVE-2023-54331HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the OutlineService executable to inject malicious code that will be…

  • CVE-2022-50933HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Cain & Abel 4.9.56 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with LocalSystem…

  • CVE-2022-50928HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    BlueSoleilCS 5.4.277 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path in 'C:\Program Files\IVT…

  • CVE-2022-50923HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Cobian Backup 0.9 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the CobianReflectorService to inject malicious code that will execute with…