VYPR

CWE-428

Unquoted Search Path or Element

BaseDraft

Description

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

If a malicious individual has access to the file system, it is possible to elevate privileges by inserting such a file as "C:\Program.exe" to be run by a privileged program making use of WinExec.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (454)

page 14 of 23
  • CVE-2022-27088HigApr 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Ivanti DSM Remote <= 6.3.1.1862 is vulnerable to an unquoted service path allowing local users to launch processes with elevated privileges.

  • CVE-2021-43463HigApr 4, 2022
    risk 0.51cvss 7.8epss 0.00

    An Unquoted Service Path vulnerability exists in Ext2Fsd v0.68 via a specially crafted file in the Ext2Srv Service executable service path.

  • CVE-2021-43460HigApr 4, 2022
    risk 0.51cvss 7.8epss 0.00

    An Unquoted Service Path vulnerability exists in System Explorer 7.0.0 via via a specially crafted file in the SystemExplorerHelpService service executable path.

  • CVE-2021-43458HigApr 4, 2022
    risk 0.51cvss 7.8epss 0.00

    An Unquoted Service Path vulnerability exits in Vembu BDR 4.2.0.1 via a specially crafted file in the (1) hsflowd, (2) VembuBDR360Agent, or (3) VembuOffice365Agent service paths.

  • CVE-2021-43457HigApr 4, 2022
    risk 0.51cvss 7.8epss 0.00

    An Unquoted Service Path vulnerability exists in bVPN 2.5.1 via a specially crafted file in the waselvpnserv service path.

  • CVE-2021-43456HigApr 4, 2022
    risk 0.51cvss 7.8epss 0.00

    An Unquoted Service Path vulnerablility exists in Rumble Mail Server 0.51.3135 via via a specially crafted file in the RumbleService executable service path.

  • CVE-2021-43455HigApr 4, 2022
    risk 0.51cvss 7.8epss 0.00

    An Unquoted Service Path vulnerability exists in FreeLAN 2.2 via a specially crafted file in the FreeLAN Service path.

  • CVE-2021-43454HigApr 4, 2022
    risk 0.51cvss 7.8epss 0.00

    An Unquoted Service Path vulnerability exists in AnyTXT Searcher 1.2.394 via a specially crafted file in the ATService path. .

  • CVE-2022-27052HigMar 31, 2022
    risk 0.51cvss 7.8epss 0.00

    FreeFtpd version 1.0.13 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.

  • CVE-2022-27050HigMar 31, 2022
    risk 0.51cvss 7.8epss 0.00

    BitComet Service for Windows before version 1.8.6 contains an unquoted service path vulnerability which allows attackers to escalate privileges to the system level.

  • CVE-2022-25031HigMar 3, 2022
    risk 0.51cvss 7.8epss 0.00

    Remote Desktop Commander Suite Agent before v4.8 contains an unquoted service path which allows attackers to escalate privileges to the system level.

  • CVE-2021-46368HigFeb 17, 2022
    risk 0.51cvss 7.8epss 0.00

    TRIGONE Remote System Monitor 3.61 is vulnerable to an unquoted path service allowing local users to launch processes with elevated privileges.

  • CVE-2021-33095HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Unquoted search path in the installer for the Intel(R) NUC M15 Laptop Kit Keyboard LED Service driver pack before version 1.0.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-42563HigNov 12, 2021
    risk 0.51cvss 7.8epss 0.00

    There is an Unquoted Service Path in NI Service Locator (nisvcloc.exe) in versions prior to 18.0 on Windows. This may allow an authorized local user to insert arbitrary code into the unquoted service path and escalate privileges.

  • CVE-2021-40683HigOct 4, 2021
    risk 0.51cvss 7.8epss 0.00

    In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquoted path may allow an attacker to hijack the flow of execution.

  • CVE-2020-11632HigJul 15, 2021
    risk 0.51cvss 7.8epss 0.00

    The Zscaler Client Connector prior to 2.1.2.150 did not quote the search path for services, which allows a local adversary to execute code with system privileges.

  • CVE-2021-35469HigJul 14, 2021
    risk 0.51cvss 7.8epss 0.00

    The Lexmark Printer Software G2, G3 and G4 Installation Packages have a local escalation of privilege vulnerability due to a registry entry that has an unquoted service path.

  • CVE-2020-22809HigMay 10, 2021
    risk 0.51cvss 7.8epss 0.00

    In Windscribe v1.83 Build 20, 'WindscribeService' has an Unquoted Service Path that facilitates privilege escalation.

  • CVE-2021-31776HigApr 29, 2021
    risk 0.51cvss 7.8epss 0.00

    Aviatrix VPN Client before 2.14.14 on Windows has an unquoted search path that enables local privilege escalation to the SYSTEM user, if the machine is misconfigured to allow unprivileged users to write to directories that are supposed to be restricted to administrators.

  • CVE-2020-7331HigNov 12, 2020
    risk 0.51cvss 7.8epss 0.00

    Unquoted service executable path in McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows local users to cause a denial of service and malicious file execution via carefully crafted and named executable files.