VYPR

CWE-428

Unquoted Search Path or Element

BaseDraft

Description

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

If a malicious individual has access to the file system, it is possible to elevate privileges by inserting such a file as "C:\Program.exe" to be run by a privileged program making use of WinExec.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (454)

page 18 of 23
  • CVE-2019-16647HigOct 29, 2019
    risk 0.47cvss 7.2epss 0.02

    Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows.

  • CVE-2026-2542HigFeb 16, 2026
    risk 0.46cvss 7.0epss 0.00

    A weakness has been identified in Total VPN 0.5.29.0 on Windows. Affected by this vulnerability is an unknown functionality of the file C:\Program Files\Total VPN\win-service.exe. Executing a manipulation can lead to unquoted search path. It is possible to launch the attack on…

  • CVE-2025-66269HigNov 26, 2025
    risk 0.46cvss epss 0.00

    The RupsMon and USBMate services in UPSilon 2000 run with SYSTEM privileges and contain unquoted service paths. This allows a local attacker to perform path interception and escalate privileges if they have write permissions to the directories proceeding that of which the real…

  • CVE-2025-13433HigNov 20, 2025
    risk 0.46cvss 7.0epss 0.00

    A security flaw has been discovered in Muse Group MuseHub 2.1.0.1567. The affected element is an unknown function of the file C:\Program Files\WindowsApps\Muse.MuseHub_2.1.0.1567_x64__rb9pth70m6nz6\Muse.Updater.exe of the component Windows Service. The manipulation results in…

  • CVE-2025-12286HigOct 27, 2025
    risk 0.46cvss 7.0epss 0.00

    A weakness has been identified in VeePN up to 1.6.2. This affects an unknown function of the file C:\Program Files (x86)\VeePN\avservice\avservice.exe of the component AVService. This manipulation causes unquoted search path. The attack requires local access. A high degree of…

  • CVE-2025-12247HigOct 27, 2025
    risk 0.46cvss 7.0epss 0.00

    A weakness has been identified in Hasleo Backup Suite up to 5.2. Impacted is an unknown function of the component HasleoImageMountService/HasleoBackupSuiteService. This manipulation causes unquoted search path. The attack is restricted to local execution. The attack's complexity…

  • CVE-2025-4540HigMay 11, 2025
    risk 0.46cvss 7.0epss 0.00

    A vulnerability was found in MTSoftware C-Lodop 6.6.1.1 on Windows. It has been rated as critical. This issue affects some unknown processing of the component CLodopPrintService. The manipulation leads to unquoted search path. The attack needs to be approached locally. The…

  • CVE-2024-3640HigMay 16, 2024
    risk 0.46cvss epss 0.00

    An unquoted executable path exists in the Rockwell Automation FactoryTalk® Remote Access™ possibly resulting in remote code execution if exploited. While running the FTRA installer package, the executable path is not properly quoted, which could allow a threat actor to enter…

  • CVE-2023-0887HigFeb 17, 2023
    risk 0.46cvss 7.0epss 0.00

    A vulnerability was found in phjounin TFTPD64-SE 4.64 and classified as critical. This issue affects some unknown processing of the file tftpd64_svc.exe. The manipulation leads to unquoted search path. An attack has to be approached locally. The complexity of an attack is rather…

  • CVE-2020-28209HigNov 19, 2020
    risk 0.46cvss 7.0epss 0.00

    A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user who has write permission on at least one of the subfolders…

  • CVE-2025-34499MedDec 11, 2025
    risk 0.45cvss epss 0.00

    AnyDesk 7.0.15 and 9.0.1 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated SYSTEM privileges. Attackers can exploit the unquoted service path configuration to inject malicious executables that will be…

  • CVE-2026-7280MedApr 28, 2026
    risk 0.44cvss 6.7epss 0.00

    AVACAST developed by eMPIA Technology has a Unquoted Service Path vulnerability, allowing privileged local attackers to place a malicious executable file in a specific directory, resulting in arbitrary code execution with system privileges when the AVACAST service starts.

  • CVE-2026-33253MedMar 25, 2026
    risk 0.44cvss 6.7epss 0.00

    SANUPS SOFTWARE provided by SANYO DENKI CO., LTD. registers Windows services with unquoted file paths. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.

  • CVE-2026-26033MedMar 5, 2026
    risk 0.44cvss 6.7epss 0.00

    UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Unquoted Search Path or Element (CWE-428) vulnerability, which allows a user with write access to a directory on the system drive to execute arbitrary code with SYSTEM privileges.

  • CVE-2026-1585MedFeb 27, 2026
    risk 0.44cvss 6.7epss 0.00

    An unquoted Windows service executable path vulnerability in IJ Scan Utility for Windows versions 1.1.2 through 1.5.0 may allow a local attacker to execute a malicious file with the privileges of the affected service.

  • CVE-2026-24466MedFeb 9, 2026
    risk 0.44cvss 6.7epss 0.00

    Products provided by Oki Electric Industry Co., Ltd. and its OEM products (Ricoh Co., Ltd., Murata Machinery, Ltd.) register Windows services with unquoted file paths. A user with the write permission on the root directory of the system drive may execute arbitrary code with…

  • CVE-2025-59888MedDec 26, 2025
    risk 0.44cvss 6.7epss 0.00

    Improper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the file system. This security issue has been fixed in the latest version of EUC which is available on the Eaton download…

  • CVE-2025-66271MedDec 9, 2025
    risk 0.44cvss 6.7epss 0.00

    Clone for Windows provided by ELECOM CO.,LTD. registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.

  • CVE-2025-66461MedDec 8, 2025
    risk 0.44cvss 6.7epss 0.00

    FULLBACK Manager Pro provided by GS Yuasa International Ltd. registers two Windows services with unquoted file paths. A user may execute arbitrary code with SYSTEM privilege if he/she has the write permission on the path to the directory where the affected product is installed.

  • CVE-2025-32449MedNov 11, 2025
    risk 0.44cvss 6.7epss 0.00

    Unquoted search path for some PRI Driver software before version 03.03.1002 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of…