VYPR

CWE-428

Unquoted Search Path or Element

BaseDraft

Description

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

If a malicious individual has access to the file system, it is possible to elevate privileges by inserting such a file as "C:\Program.exe" to be run by a privileged program making use of WinExec.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (454)

page 20 of 23
  • CVE-2023-27386MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) Pathfinder for RISC-V software may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-43474MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for the DSP Builder software installer before version 22.4 for Intel(R) FPGAs Pro Edition may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-41693MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in the Intel(R) Quartus(R) Prime Pro edition software before version 22.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-38101MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in some Intel(R) NUC Chaco Canyon BIOS update software before version iFlashV Windows 5.13.00.2105 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-34848MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-46662MedDec 21, 2022
    risk 0.44cvss 6.7epss 0.00

    Roxio Creator LJB starts another program with an unquoted file path. Since a registered Windows service path contains spaces and are unquoted, if a malicious executable is placed on a certain path, the executable may be executed with the privilege of the Windows service. The…

  • CVE-2022-36384MedNov 11, 2022
    risk 0.44cvss 6.7epss 0.00

    Unquoted search path in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-27094MedMay 20, 2022
    risk 0.44cvss 6.7epss 0.00

    Sony PlayMemories Home v6.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.

  • CVE-2021-29218MedFeb 4, 2022
    risk 0.44cvss 6.7epss 0.00

    A local unquoted search path security vulnerability has been identified in HPE Agentless Management Service for Windows version(s): Prior to 1.44.0.0, 10.96.0.0. This vulnerability could be exploited locally by a user with high privileges to execute malware that may lead to a…

  • CVE-2021-35231MedOct 25, 2021
    risk 0.44cvss 6.7epss 0.00

    As a result of an unquoted service path vulnerability present in the Kiwi Syslog Server Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or uninstall entry. Example vulnerable path:…

  • CVE-2021-35056MedJul 15, 2021
    risk 0.44cvss 6.7epss 0.00

    Unisys Stealth 5.1 before 5.1.025.0 and 6.0 before 6.0.055.0 has an unquoted Windows search path for a scheduled task. An unintended executable might run.

  • CVE-2021-23879MedMar 15, 2021
    risk 0.44cvss 6.7epss 0.00

    Unquoted service path vulnerability in McAfee Endpoint Product Removal (EPR) Tool prior to 21.2 allows local administrators to execute arbitrary code, with higher-level privileges, via execution from a compromised folder. The tool did not enforce and protect the execution path.…

  • CVE-2020-7382MedSep 3, 2020
    risk 0.44cvss 6.8epss 0.00

    Rapid7 Nexpose installer version prior to 6.6.40 contains an Unquoted Search Path which may allow an attacker on the local machine to insert an arbitrary file into the executable path. This issue affects: Rapid7 Nexpose versions prior to 6.6.40.

  • CVE-2020-7581MedJul 14, 2020
    risk 0.44cvss 6.7epss 0.00

    A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcenter Intelligence (All versions < V3.3), Opcenter Quality (All versions < V11.3),…

  • CVE-2020-7580MedJun 10, 2020
    risk 0.44cvss 6.7epss 0.00

    A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC Software V16 (All versions < V16 Upd3), SIMATIC PCS neo (All…

  • CVE-2020-8337MedJun 9, 2020
    risk 0.44cvss 6.7epss 0.00

    An unquoted search path vulnerability was reported in versions prior to 1.0.83.0 of the Synaptics Smart Audio UWP app associated with the DCHU audio drivers on Lenovo platforms that could allow an administrative user to execute arbitrary code.

  • CVE-2019-6145MedSep 20, 2019
    risk 0.44cvss 6.7epss 0.01

    Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability. This enables local privilege escalation to SYSTEM user. By default, only local administrators can write executables to the vulnerable directories. Forcepoint thanks Peleg…

  • CVE-2019-7590MedJul 19, 2019
    risk 0.44cvss 6.7epss 0.01

    ExacqVision Server’s services 'exacqVisionServer', 'dvrdhcpserver' and 'mdnsresponder' have an unquoted service path. If an authenticated user is able to insert code in their system root path it potentially can be executed during the application startup. This could allow the…

  • CVE-2019-11093MedMay 17, 2019
    risk 0.44cvss 6.7epss 0.00

    Unquoted service path in the installer for the Intel(R) SCS Discovery Utility version 12.0.0.129 and earlier may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2019-6149MedMar 18, 2019
    risk 0.44cvss 6.7epss 0.00

    An unquoted search path vulnerability was identified in Lenovo Dynamic Power Reduction Utility prior to version 2.2.2.0 that could allow a malicious user with local access to execute code with administrative privileges.