VYPR

CWE-428

Unquoted Search Path or Element

BaseDraft

Description

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

If a malicious individual has access to the file system, it is possible to elevate privileges by inserting such a file as "C:\Program.exe" to be run by a privileged program making use of WinExec.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (454)

page 13 of 23
  • CVE-2023-37537HigOct 17, 2023
    risk 0.51cvss 7.8epss 0.00

    An unquoted service path vulnerability in HCL AppScan Presence, deployed as a Windows service in HCL AppScan on Cloud (ASoC), may allow a local attacker to gain elevated privileges.

  • CVE-2023-4991HigSep 15, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in NextBX QWAlerter 4.50. It has been rated as critical. Affected by this issue is some unknown functionality of the file QWAlerter.exe. The manipulation leads to unquoted search path. It is possible to launch the attack on the local host. The…

  • CVE-2023-36658HigSep 15, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. It has an unquoted service path that can be abused locally.

  • CVE-2023-26911HigJul 26, 2023
    risk 0.51cvss 7.8epss 0.00

    ASUS SetupAsusServices v1.0.5.1 in Asus Armoury Crate v5.3.4.0 contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.

  • CVE-2023-3842HigJul 23, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in Pointware EasyInventory 1.0.12.0 and classified as critical. This issue affects some unknown processing of the file C:\Program Files (x86)\EasyInventory\Easy2W.exe. The manipulation leads to unquoted search path. Attacking locally is a requirement.…

  • CVE-2023-2331HigApr 27, 2023
    risk 0.51cvss 7.8epss 0.00

    Unquoted service Path or Element vulnerability in 42Gears Surelock Windows SureLock Service (NixService.Exe) on Windows application will allows to insert arbitrary code into the service. This issue affects Surelock Windows : from 2.3.12 through 2.40.0.

  • CVE-2023-24671HigMar 16, 2023
    risk 0.51cvss 7.8epss 0.00

    VX Search v13.8 and v14.7 was discovered to contain an unquoted service path vulnerability which allows attackers to execute arbitrary commands at elevated privileges via a crafted executable file.

  • CVE-2023-24575HigFeb 21, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell Multifunction Printer E525w Driver and Software Suite, versions prior to 1.047.2022, A05, contain a local privilege escalation vulnerability that could be exploited by malicious users to compromise the affected system

  • CVE-2022-44264HigJan 26, 2023
    risk 0.51cvss 7.8epss 0.00

    Dentsply Sirona Sidexis <= 4.3 is vulnerable to Unquoted Service Path.

  • CVE-2022-4258HigJan 16, 2023
    risk 0.51cvss 7.8epss 0.00

    In multiple versions of HIMA PC based Software an unquoted Windows search path vulnerability might allow local users to gain privileges via a malicious .exe file and gain full access to the system.

  • CVE-2019-19705HigDec 26, 2022
    risk 0.51cvss 7.8epss 0.00

    Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG before 6.0.8907.1 (and on many other Lenovo and non-Lenovo products), mishandles DLL preloading.

  • CVE-2022-33920HigOct 12, 2022
    risk 0.51cvss 7.8epss 0.00

    Dell GeoDrive, versions prior to 2.2, contains an Unquoted File Path vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to the execution of arbitrary code in the SYSTEM security context.

  • CVE-2022-39959HigOct 7, 2022
    risk 0.51cvss 7.8epss 0.01

    Panini Everest Engine 2.0.4 allows unprivileged users to create a file named Everest.exe in the %PROGRAMDATA%\Panini folder. This leads to privilege escalation because a service, running as SYSTEM, uses the unquoted path of %PROGRAMDATA%\Panini\Everest Engine\EverestEngine.exe…

  • CVE-2022-35292HigSep 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In SAP Business One application when a service is created, the executable path contains spaces and isn’t enclosed within quotes, leading to a vulnerability known as Unquoted Service Path which allows a user to gain SYSTEM privileges. If the service is exploited by adversaries,…

  • CVE-2022-31591HigJul 12, 2022
    risk 0.51cvss 7.8epss 0.00

    SAP BusinessObjects BW Publisher Service - versions 420, 430, uses a search path that contains an unquoted element. A local attacker can gain elevated privileges by inserting an executable file in the path of the affected service

  • CVE-2022-31590HigJun 14, 2022
    risk 0.51cvss 7.8epss 0.00

    SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to work around system’s root disk access restrictions to Write/Create a program file on system disk root path, which could then be executed with elevated…

  • CVE-2022-29320HigMay 20, 2022
    risk 0.51cvss 7.8epss 0.00

    MiniTool Partition Wizard v12.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.

  • CVE-2022-27095HigMay 20, 2022
    risk 0.51cvss 7.8epss 0.00

    BattlEye v0.9 contains an unquoted service path which allows attackers to escalate privileges to the system level.

  • CVE-2022-26634HigMay 20, 2022
    risk 0.51cvss 7.8epss 0.00

    HMA VPN v5.3.5913.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.

  • CVE-2022-27089HigApr 11, 2022
    risk 0.51cvss 7.8epss 0.00

    In Fujitsu PlugFree Network <= 7.3.0.3, an Unquoted service path in PFNService.exe software allows a local attacker to potentially escalate privileges to system level.