VYPR

CWE-428

Unquoted Search Path or Element

BaseDraft

Description

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

If a malicious individual has access to the file system, it is possible to elevate privileges by inserting such a file as "C:\Program.exe" to be run by a privileged program making use of WinExec.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (454)

page 21 of 23
  • CVE-2018-14789MedAug 22, 2018
    risk 0.44cvss 6.7epss 0.00

    In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 3.1 or prior and Xcelera Version 4.1 or prior), an unquoted search path or element vulnerability has been identified, which may allow an attacker to execute arbitrary code and escalate their level of…

  • CVE-2017-14019MedOct 19, 2017
    risk 0.44cvss 6.7epss 0.00

    An Unquoted Search Path or Element issue was discovered in Progea Movicon Version 11.5.1181 and prior. An unquoted search path or element vulnerability has been identified, which may allow an authorized local user to insert arbitrary code into the unquoted service path and…

  • CVE-2017-5873MedApr 11, 2017
    risk 0.44cvss 6.7epss 0.00

    Unquoted Windows search path vulnerability in the guest service in Unisys s-Par before 4.4.20 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe.

  • CVE-2025-24831MedJan 31, 2025
    risk 0.43cvss 6.6epss 0.00

    Local privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.

  • CVE-2020-7316MedOct 7, 2020
    risk 0.43cvss 6.6epss 0.00

    Unquoted service path vulnerability in McAfee File and Removable Media Protection (FRP) prior to 5.3.0 allows local users to execute arbitrary code, with higher privileges, via execution and from a compromised folder. This issue may result in files not being encrypted when a…

  • CVE-2024-31201MedJul 31, 2024
    risk 0.42cvss 6.5epss 0.00

    A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service. Such misconfiguration could be abused in scenarios where incorrect permissions were assigned to the C:\ path to attempt a privilege escalation on the local machine.

  • CVE-2022-2147MedJun 23, 2022
    risk 0.42cvss 6.5epss 0.00

    Cloudflare Warp for Windows from version 2022.2.95.0 contained an unquoted service path which enables arbitrary code execution leading to privilege escalation. The fix was released in version 2022.3.186.0.

  • CVE-2022-27966MedMar 31, 2022
    risk 0.42cvss 6.5epss 0.00

    Xshell v7.0.0099 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.

  • CVE-2022-27965MedMar 31, 2022
    risk 0.42cvss 6.5epss 0.00

    Xlpd v7.0.0094 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.

  • CVE-2022-27964MedMar 31, 2022
    risk 0.42cvss 6.5epss 0.00

    Xmanager v7.0.0096 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.

  • CVE-2022-27963MedMar 31, 2022
    risk 0.42cvss 6.5epss 0.00

    Xftp 7.0.0088p and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.

  • CVE-2021-45819MedMar 3, 2022
    risk 0.42cvss 6.4epss 0.00

    Wordline HIDCCEMonitorSVC before v5.2.4.3 contains an unquoted service path which allows attackers to escalate privileges to the system level.

  • CVE-2021-31553MedApr 22, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in the CheckUser extension for MediaWiki through 1.35.2. MediaWiki usernames with trailing whitespace could be stored in the cu_log database table such that denial of service occurred for certain CheckUser extension pages and functionality. For example,…

  • CVE-2023-42486MedSep 27, 2023
    risk 0.41cvss 6.3epss 0.00

    Fortect - CWE-428: Unquoted Search Path or Element, may be used by local user to elevate privileges.

  • CVE-2016-15003MedJul 18, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability has been found in FileZilla Client 3.17.0.0 and classified as problematic. This vulnerability affects unknown code of the file C:\Program Files\FileZilla FTP Client\uninstall.exe of the component Installer. The manipulation leads to unquoted search path. The…

  • CVE-2023-53954MedDec 19, 2025
    risk 0.40cvss 6.2epss 0.00

    ActFax 10.10 contains an unquoted service path vulnerability that allows local attackers to potentially escalate privileges by exploiting the ActiveFaxServiceNT service configuration. Attackers with write permissions to Program Files directories can inject a malicious…

  • CVE-2023-53912MedDec 17, 2025
    risk 0.40cvss 6.2epss 0.00

    USB Flash Drives Control 4.1.0.0 contains an unquoted service path vulnerability in its service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\USB Flash Drives Control\usbcs.exe' to…

  • CVE-2024-8996HigSep 25, 2024
    risk 0.40cvss 7.3epss 0.00

    Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Agent Flow: before 0.43.2

  • CVE-2024-8975HigSep 25, 2024
    risk 0.40cvss 7.3epss 0.00

    Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Alloy: before 1.3.3, from 1.4.0-rc.0 through 1.4.0-rc.1.

  • CVE-2020-5147MedJan 9, 2021
    risk 0.38cvss 5.3epss 0.02

    SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated privileges in the host operating system. This vulnerability impact SonicWall NetExtender Windows client version 10.2.300 and earlier.