CWE-428
Unquoted Search Path or Element
Description
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (454)
page 13 of 23| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-37537 | Hig | 0.51 | 7.8 | 0.00 | Oct 17, 2023 | An unquoted service path vulnerability in HCL AppScan Presence, deployed as a Windows service in HCL AppScan on Cloud (ASoC), may allow a local attacker to gain elevated privileges. | ||
| CVE-2023-4991 | Hig | 0.51 | 7.8 | 0.00 | Sep 15, 2023 | A vulnerability was found in NextBX QWAlerter 4.50. It has been rated as critical. Affected by this issue is some unknown functionality of the file QWAlerter.exe. The manipulation leads to unquoted search path. It is possible to launch the attack on the local host. The… | ||
| CVE-2023-36658 | Hig | 0.51 | 7.8 | 0.00 | Sep 15, 2023 | An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. It has an unquoted service path that can be abused locally. | ||
| CVE-2023-26911 | Hig | 0.51 | 7.8 | 0.00 | Jul 26, 2023 | ASUS SetupAsusServices v1.0.5.1 in Asus Armoury Crate v5.3.4.0 contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges. | ||
| CVE-2023-3842 | Hig | 0.51 | 7.8 | 0.00 | Jul 23, 2023 | A vulnerability was found in Pointware EasyInventory 1.0.12.0 and classified as critical. This issue affects some unknown processing of the file C:\Program Files (x86)\EasyInventory\Easy2W.exe. The manipulation leads to unquoted search path. Attacking locally is a requirement.… | ||
| CVE-2023-2331 | Hig | 0.51 | 7.8 | 0.00 | Apr 27, 2023 | Unquoted service Path or Element vulnerability in 42Gears Surelock Windows SureLock Service (NixService.Exe) on Windows application will allows to insert arbitrary code into the service. This issue affects Surelock Windows : from 2.3.12 through 2.40.0. | ||
| CVE-2023-24671 | Hig | 0.51 | 7.8 | 0.00 | Mar 16, 2023 | VX Search v13.8 and v14.7 was discovered to contain an unquoted service path vulnerability which allows attackers to execute arbitrary commands at elevated privileges via a crafted executable file. | ||
| CVE-2023-24575 | Hig | 0.51 | 7.8 | 0.00 | Feb 21, 2023 | Dell Multifunction Printer E525w Driver and Software Suite, versions prior to 1.047.2022, A05, contain a local privilege escalation vulnerability that could be exploited by malicious users to compromise the affected system | ||
| CVE-2022-44264 | Hig | 0.51 | 7.8 | 0.00 | Jan 26, 2023 | Dentsply Sirona Sidexis <= 4.3 is vulnerable to Unquoted Service Path. | ||
| CVE-2022-4258 | Hig | 0.51 | 7.8 | 0.00 | Jan 16, 2023 | In multiple versions of HIMA PC based Software an unquoted Windows search path vulnerability might allow local users to gain privileges via a malicious .exe file and gain full access to the system. | ||
| CVE-2019-19705 | Hig | 0.51 | 7.8 | 0.00 | Dec 26, 2022 | Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG before 6.0.8907.1 (and on many other Lenovo and non-Lenovo products), mishandles DLL preloading. | ||
| CVE-2022-33920 | Hig | 0.51 | 7.8 | 0.00 | Oct 12, 2022 | Dell GeoDrive, versions prior to 2.2, contains an Unquoted File Path vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to the execution of arbitrary code in the SYSTEM security context. | ||
| CVE-2022-39959 | Hig | 0.51 | 7.8 | 0.01 | Oct 7, 2022 | Panini Everest Engine 2.0.4 allows unprivileged users to create a file named Everest.exe in the %PROGRAMDATA%\Panini folder. This leads to privilege escalation because a service, running as SYSTEM, uses the unquoted path of %PROGRAMDATA%\Panini\Everest Engine\EverestEngine.exe… | ||
| CVE-2022-35292 | Hig | 0.51 | 7.8 | 0.00 | Sep 13, 2022 | In SAP Business One application when a service is created, the executable path contains spaces and isn’t enclosed within quotes, leading to a vulnerability known as Unquoted Service Path which allows a user to gain SYSTEM privileges. If the service is exploited by adversaries,… | ||
| CVE-2022-31591 | Hig | 0.51 | 7.8 | 0.00 | Jul 12, 2022 | SAP BusinessObjects BW Publisher Service - versions 420, 430, uses a search path that contains an unquoted element. A local attacker can gain elevated privileges by inserting an executable file in the path of the affected service | ||
| CVE-2022-31590 | Hig | 0.51 | 7.8 | 0.00 | Jun 14, 2022 | SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to work around system’s root disk access restrictions to Write/Create a program file on system disk root path, which could then be executed with elevated… | ||
| CVE-2022-29320 | Hig | 0.51 | 7.8 | 0.00 | May 20, 2022 | MiniTool Partition Wizard v12.0 contains an unquoted service path which allows attackers to escalate privileges to the system level. | ||
| CVE-2022-27095 | Hig | 0.51 | 7.8 | 0.00 | May 20, 2022 | BattlEye v0.9 contains an unquoted service path which allows attackers to escalate privileges to the system level. | ||
| CVE-2022-26634 | Hig | 0.51 | 7.8 | 0.00 | May 20, 2022 | HMA VPN v5.3.5913.0 contains an unquoted service path which allows attackers to escalate privileges to the system level. | ||
| CVE-2022-27089 | Hig | 0.51 | 7.8 | 0.00 | Apr 11, 2022 | In Fujitsu PlugFree Network <= 7.3.0.3, an Unquoted service path in PFNService.exe software allows a local attacker to potentially escalate privileges to system level. |
- risk 0.51cvss 7.8epss 0.00
An unquoted service path vulnerability in HCL AppScan Presence, deployed as a Windows service in HCL AppScan on Cloud (ASoC), may allow a local attacker to gain elevated privileges.
- risk 0.51cvss 7.8epss 0.00
A vulnerability was found in NextBX QWAlerter 4.50. It has been rated as critical. Affected by this issue is some unknown functionality of the file QWAlerter.exe. The manipulation leads to unquoted search path. It is possible to launch the attack on the local host. The…
- risk 0.51cvss 7.8epss 0.00
An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. It has an unquoted service path that can be abused locally.
- risk 0.51cvss 7.8epss 0.00
ASUS SetupAsusServices v1.0.5.1 in Asus Armoury Crate v5.3.4.0 contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.
- risk 0.51cvss 7.8epss 0.00
A vulnerability was found in Pointware EasyInventory 1.0.12.0 and classified as critical. This issue affects some unknown processing of the file C:\Program Files (x86)\EasyInventory\Easy2W.exe. The manipulation leads to unquoted search path. Attacking locally is a requirement.…
- risk 0.51cvss 7.8epss 0.00
Unquoted service Path or Element vulnerability in 42Gears Surelock Windows SureLock Service (NixService.Exe) on Windows application will allows to insert arbitrary code into the service. This issue affects Surelock Windows : from 2.3.12 through 2.40.0.
- risk 0.51cvss 7.8epss 0.00
VX Search v13.8 and v14.7 was discovered to contain an unquoted service path vulnerability which allows attackers to execute arbitrary commands at elevated privileges via a crafted executable file.
- risk 0.51cvss 7.8epss 0.00
Dell Multifunction Printer E525w Driver and Software Suite, versions prior to 1.047.2022, A05, contain a local privilege escalation vulnerability that could be exploited by malicious users to compromise the affected system
- risk 0.51cvss 7.8epss 0.00
Dentsply Sirona Sidexis <= 4.3 is vulnerable to Unquoted Service Path.
- risk 0.51cvss 7.8epss 0.00
In multiple versions of HIMA PC based Software an unquoted Windows search path vulnerability might allow local users to gain privileges via a malicious .exe file and gain full access to the system.
- risk 0.51cvss 7.8epss 0.00
Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG before 6.0.8907.1 (and on many other Lenovo and non-Lenovo products), mishandles DLL preloading.
- risk 0.51cvss 7.8epss 0.00
Dell GeoDrive, versions prior to 2.2, contains an Unquoted File Path vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to the execution of arbitrary code in the SYSTEM security context.
- risk 0.51cvss 7.8epss 0.01
Panini Everest Engine 2.0.4 allows unprivileged users to create a file named Everest.exe in the %PROGRAMDATA%\Panini folder. This leads to privilege escalation because a service, running as SYSTEM, uses the unquoted path of %PROGRAMDATA%\Panini\Everest Engine\EverestEngine.exe…
- risk 0.51cvss 7.8epss 0.00
In SAP Business One application when a service is created, the executable path contains spaces and isn’t enclosed within quotes, leading to a vulnerability known as Unquoted Service Path which allows a user to gain SYSTEM privileges. If the service is exploited by adversaries,…
- risk 0.51cvss 7.8epss 0.00
SAP BusinessObjects BW Publisher Service - versions 420, 430, uses a search path that contains an unquoted element. A local attacker can gain elevated privileges by inserting an executable file in the path of the affected service
- risk 0.51cvss 7.8epss 0.00
SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to work around system’s root disk access restrictions to Write/Create a program file on system disk root path, which could then be executed with elevated…
- risk 0.51cvss 7.8epss 0.00
MiniTool Partition Wizard v12.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.
- risk 0.51cvss 7.8epss 0.00
BattlEye v0.9 contains an unquoted service path which allows attackers to escalate privileges to the system level.
- risk 0.51cvss 7.8epss 0.00
HMA VPN v5.3.5913.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.
- risk 0.51cvss 7.8epss 0.00
In Fujitsu PlugFree Network <= 7.3.0.3, an Unquoted service path in PFNService.exe software allows a local attacker to potentially escalate privileges to system level.