VYPR

CWE-428

Unquoted Search Path or Element

BaseDraft

Description

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

If a malicious individual has access to the file system, it is possible to elevate privileges by inserting such a file as "C:\Program.exe" to be run by a privileged program making use of WinExec.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (454)

page 17 of 23
  • CVE-2026-9128HigJul 14, 2026
    risk 0.49cvss epss 0.00

    A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these…

  • CVE-2021-27608HigApr 14, 2021
    risk 0.49cvss 7.5epss 0.00

    An unquoted service path in SAPSetup, version - 9.0, could lead to privilege escalation during the installation process that is performed when an executable file is registered. This could further lead to complete compromise of confidentiality, Integrity and Availability.

  • CVE-2017-9644HigAug 25, 2017
    risk 0.49cvss 7.0epss 0.01

    An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL,…

  • CVE-2025-66264HigNov 26, 2025
    risk 0.47cvss epss 0.00

    The CMService.exe service runs with SYSTEM privileges and contains an unquoted service path. This allows a local attacker with write privileges to the filesystem to insert a malicious executable in the path, leading to privilege escalation.

  • CVE-2025-5191HigAug 25, 2025
    risk 0.47cvss epss 0.00

    An Unquoted Search Path vulnerability has been identified in the utility for Moxa’s industrial computers (Windows). Due to the unquoted path configuration in the SerialInterfaceService.exe utility, a local attacker with limited privileges could place a malicious executable in…

  • CVE-2025-0035HigMay 13, 2025
    risk 0.47cvss 7.3epss 0.00

    Unquoted search path within AMD Cloud Manageability Service can allow a local attacker to escalate privileges, potentially resulting in arbitrary code execution.

  • CVE-2024-36321HigMay 13, 2025
    risk 0.47cvss 7.3epss 0.00

    Unquoted search path within AIM-T Manageability Service can allow a local attacker to escalate privileges, potentially resulting in arbitrary code execution.

  • CVE-2025-0884HigMar 12, 2025
    risk 0.47cvss epss 0.00

    Unquoted Search Path or Element vulnerability in OpenText™ Service Manager.  The vulnerability could allow a user to gain SYSTEM privileges through Privilege Escalation. This issue affects Service Manager: 9.70, 9.71, 9.72.

  • CVE-2024-57276HigJan 27, 2025
    risk 0.47cvss 7.3epss 0.00

    In Electronic Arts Dragon Age Origins 1.05, the DAUpdaterSVC service contains an unquoted service path vulnerability. This service is configured with insecure permissions, allowing users to modify the executable file path used by the service. The service runs with NT…

  • CVE-2023-39464HigMay 3, 2024
    risk 0.47cvss 7.2epss 0.02

    Triangle MicroWorks SCADA Data Gateway GTWWebMonitorService Unquoted Search Path Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute code on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is…

  • CVE-2024-31804MedApr 23, 2024
    risk 0.47cvss 6.7epss 0.01

    An unquoted service path vulnerability in Terratec DMX_6Fire USB v.1.23.0.02 allows a local attacker to escalate privileges via the Program.exe component.

  • CVE-2024-22437HigApr 15, 2024
    risk 0.47cvss 7.3epss 0.00

    A potential security vulnerability has been identified in VSS Provider and CAPI Proxy software for certain HPE MSA storage products. This vulnerability could be exploited to gain elevated privilege on the system.

  • CVE-2020-24682HigFeb 2, 2024
    risk 0.47cvss 7.2epss 0.00

    Unquoted Search Path or Element vulnerability in B&R Industrial Automation Automation Studio, B&R Industrial Automation NET/PVI allows Target Programs with Elevated Privileges.This issue affects Automation Studio: from 4.0 through 4.6, from 4.7.0 before 4.7.7 SP, from 4.8.0…

  • CVE-2023-2685HigJul 28, 2023
    risk 0.47cvss 7.2epss 0.00

    A vulnerability was found in AO-OPC server versions mentioned above. As the directory information for the service entry is not enclosed in quotation marks, potential attackers could possibly call up another application than the AO-OPC server by starting the service. The service…

  • CVE-2023-22282HigApr 11, 2023
    risk 0.47cvss 7.3epss 0.00

    WAB-MAT Ver.5.0.0.8 and earlier starts another program with an unquoted file path. Since a registered Windows service path contains spaces and are unquoted, if a malicious executable is placed on a certain path, the executable may be executed with the privilege of the Windows…

  • CVE-2022-0883HigMay 18, 2022
    risk 0.47cvss 7.3epss 0.00

    SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.20.1 should be patched.

  • CVE-2022-27905HigApr 27, 2022
    risk 0.47cvss 7.2epss 0.01

    In ControlUp Real-Time Agent before 8.6, an unquoted path can result in privilege escalation. An attacker would require write permissions to the root level of the OS drive (C:\) to exploit this.

  • CVE-2021-0112HigJun 9, 2021
    risk 0.47cvss 7.3epss 0.00

    Unquoted service path in the Intel Unite(R) Client for Windows before version 4.2.25031 may allow an authenticated user to potentially enable an escalation of privilege via local access.

  • CVE-2020-8326HigJul 24, 2020
    risk 0.47cvss 7.3epss 0.00

    An unquoted service path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges.

  • CVE-2020-8327HigApr 14, 2020
    risk 0.47cvss 7.3epss 0.00

    A privilege escalation vulnerability was reported in LenovoBatteryGaugePackage for Lenovo System Interface Foundation bundled in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authenticated user to execute code with elevated privileges.