VYPR

CWE-428

Unquoted Search Path or Element

BaseDraft

Description

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

If a malicious individual has access to the file system, it is possible to elevate privileges by inserting such a file as "C:\Program.exe" to be run by a privileged program making use of WinExec.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (454)

page 15 of 23
  • CVE-2020-10051HigSep 9, 2020
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). Multiple services of the affected application are executed with SYSTEM privileges while the call path is not quoted. This could allow a local attacker to inject arbitrary commands that…

  • CVE-2020-0546HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.00

    Unquoted service path in Intel(R) Optane(TM) DC Persistent Memory Module Management Software before version 1.0.0.3461 may allow an authenticated user to potentially enable escalation of privilege and denial of service via local access.

  • CVE-2019-20357HigJan 18, 2020
    risk 0.51cvss 7.8epss 0.01

    A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain persistence on a…

  • CVE-2019-20362HigJan 8, 2020
    risk 0.51cvss 7.8epss 0.01

    In Teradici PCoIP Agent before 19.08.1 and PCoIP Client before 19.08.3, an unquoted service path can cause execution of %PROGRAMFILES(X86)%\Teradici\PCoIP.exe instead of the intended pcoip_vchan_printing_svc.exe file.

  • CVE-2019-6008HigDec 26, 2019
    risk 0.51cvss 7.8epss 0.01

    An unquoted search path vulnerability in Multiple Yokogawa products for Windows (Exaopc (R1.01.00 ? R3.77.00), Exaplog (R1.10.00 ? R3.40.00), Exaquantum (R1.10.00 ? R3.02.00 and R3.15.00), Exaquantum/Batch (R1.01.00 ? R2.50.40), Exasmoc (all revisions), Exarqe (all revisions),…

  • CVE-2019-7487HigDec 19, 2019
    risk 0.51cvss 7.8epss 0.00

    Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not put the path in quotes, so if a malicious binary by an attacker within the parent path could allow code execution.

  • CVE-2019-18245HigDec 11, 2019
    risk 0.51cvss 7.8epss 0.00

    Reliable Controls LicenseManager versions 3.4 and prior may allow an authenticated user to insert malicious code into the system root path, which may allow execution of code with elevated privileges of the application.

  • CVE-2019-7201HigDec 4, 2019
    risk 0.51cvss 7.8epss 0.00

    An unquoted service path vulnerability is reported to affect the service QVssService in QNAP NetBak Replicator. This vulnerability could allow an authorized but non-privileged local user to execute arbitrary code with elevated system privileges. QNAP have already fixed this…

  • CVE-2019-14685HigAug 21, 2019
    risk 0.51cvss 7.8epss 0.01

    A local privilege escalation vulnerability exists in Trend Micro Security 2019 (v15.0) in which, if exploited, would allow an attacker to manipulate a specific product feature to load a malicious service.

  • CVE-2018-20341HigApr 8, 2019
    risk 0.51cvss 7.8epss 0.00

    WINMAGIC SecureDoc Disk Encryption software before 8.3 has an Unquoted Service Path vulnerability, which could allow an attacker to execute arbitrary code on a target system. If the executable is enclosed in quote tags "" then the system will know where to find it. However if…

  • CVE-2018-16098HigJan 24, 2019
    risk 0.51cvss 7.8epss 0.00

    In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could allow unauthorized code execution as a low privilege user.

  • CVE-2018-16183HigJan 9, 2019
    risk 0.51cvss 7.8epss 0.01

    An unquoted search path vulnerability in some pre-installed applications on Panasonic PC run on Windows 7 (32bit), Windows 7 (64bit), Windows 8 (64bit), Windows 8.1 (64bit), Windows 10 (64bit) delivered in or later than October 2009 allow local users to gain privileges via a…

  • CVE-2018-11063HigAug 10, 2018
    risk 0.51cvss 7.8epss 0.00

    Dell WMS versions 1.1 and prior are impacted by multiple unquoted service path vulnerabilities. Affected software installs multiple services incorrectly by specifying the paths to the service executables without quotes. This could potentially allow a low-privileged local user to…

  • CVE-2018-3688HigJul 10, 2018
    risk 0.51cvss 7.8epss 0.00

    Unquoted service paths in Intel Quartus Prime Programmer and Tools in versions 15.1 - 18.0 allow a local attacker to potentially execute arbitrary code.

  • CVE-2018-3687HigJul 10, 2018
    risk 0.51cvss 7.8epss 0.00

    Unquoted service paths in Intel Quartus II Programmer and Tools in versions 11.0 - 15.0 allow a local attacker to potentially execute arbitrary code.

  • CVE-2018-3684HigJul 10, 2018
    risk 0.51cvss 7.8epss 0.00

    Unquoted service paths in Intel Quartus II in versions 11.0 - 15.0 allow a local attacker to potentially execute arbitrary code.

  • CVE-2018-3683HigJul 10, 2018
    risk 0.51cvss 7.8epss 0.00

    Unquoted service paths in Intel Quartus Prime in versions 15.1 - 18.0 allow a local attacker to potentially execute arbitrary code.

  • CVE-2018-3668HigJul 10, 2018
    risk 0.51cvss 7.8epss 0.00

    Unquoted service paths in Intel Processor Diagnostic Tool (IPDT) before version 4.1.0.27 allows a local attacker to potentially execute arbitrary code.

  • CVE-2017-11672HigJun 13, 2018
    risk 0.51cvss 7.8epss 0.00

    The OPC Foundation Local Discovery Server (LDS) before 1.03.367 is installed as a Windows Service without adding double quotes around the opcualds.exe executable path, which might allow local users to gain privileges.

  • CVE-2018-4873HigMay 19, 2018
    risk 0.51cvss 7.8epss 0.01

    Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Unquoted Search Path vulnerability. Successful exploitation could lead to local privilege escalation.