VYPR

CWE-428

Unquoted Search Path or Element

BaseDraft

Description

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

If a malicious individual has access to the file system, it is possible to elevate privileges by inserting such a file as "C:\Program.exe" to be run by a privileged program making use of WinExec.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (454)

page 22 of 23
  • CVE-2014-0759MedFeb 28, 2014
    risk 0.38cvss 5.9epss 0.00

    Unquoted Windows search path vulnerability in Schneider Electric Floating License Manager 1.0.0 through 1.4.0 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.

  • CVE-2025-39246MedAug 29, 2025
    risk 0.34cvss 5.3epss 0.00

    There is an Unquoted Service Path Vulnerability in some HikCentral FocSign versions. This could allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2025-1984MedMar 12, 2025
    risk 0.34cvss 5.2epss 0.00

    Xerox Desktop Print Experience application contains a Local Privilege Escalation (LPE) vulnerability, which allows a low-privileged user to gain SYSTEM-level access.

  • CVE-2023-5012MedSep 16, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability, which was classified as problematic, was found in Topaz OFD 2.11.0.201. This affects an unknown part of the file C:\Program Files\Topaz OFD\Warsaw\core.exe of the component Protection Module Warsaw. The manipulation leads to unquoted search path. Attacking…

  • CVE-2023-2644MedMay 11, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability, which was classified as problematic, has been found in DigitalPersona FPSensor 1.0.0.1. This issue affects some unknown processing of the file C:\Program Files (x86)\FPSensor\bin\DpHost.exe. The manipulation leads to unquoted search path. Attacking locally is a…

  • CVE-2023-2417MedApr 29, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in ks-soft Advanced Host Monitor up to 12.56 and classified as problematic. Affected by this issue is some unknown functionality of the file C:\Program Files (x86)\HostMonitor\RMA-Win\rma_active.exe. The manipulation leads to unquoted search path. It is…

  • CVE-2022-4429MedJan 10, 2023
    risk 0.34cvss 5.3epss 0.00

    Avira Security for Windows contains an unquoted service path which allows attackers with local administrative privileges to cause a Denial of Service. The issue was fixed with Avira Security version 1.1.78

  • CVE-2021-23197MedNov 18, 2021
    risk 0.34cvss 5.2epss 0.00

    Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the account that runs the Controller Service. This issue affects: Gallagher Command Centre 8.50 versions prior to 8.50.2048 (MR3) ;

  • CVE-2018-2406MedApr 10, 2018
    risk 0.34cvss 5.3epss 0.00

    Unquoted windows search path (directory/path traversal) vulnerability in Crystal Reports Server, OEM Edition (CRSE), 4.0, 4.10, 4.20, 4.30, startup path.

  • CVE-2012-0945MedJan 15, 2020
    risk 0.32cvss 4.9epss 0.01

    whoopsie-daisy before 0.1.26: Root user can remove arbitrary files

  • CVE-2020-7275MedApr 15, 2020
    risk 0.31cvss 4.8epss 0.00

    Accessing, modifying or executing executable files vulnerability in the uninstaller in McAfee Endpoint Security (ENS) for Windows Prior to 10.7.0 April 2020 Update allows local users to execute arbitrary code via a carefully crafted input file.

  • CVE-2014-5455MedAug 25, 2014
    risk 0.31cvss 5.3epss 0.01

    Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and OpenVPN Connect version 3.1 (Windows) allows local users to gain privileges via a crafted program.exe file in the %SYSTEMDRIVE% folder.

  • CVE-2026-32009MedMar 19, 2026
    risk 0.30cvss 5.7epss 0.00

    OpenClaw versions prior to 2026.2.24 contain a policy bypass vulnerability in the safeBins allowlist evaluation that trusts static default directories including writable package-manager paths like /opt/homebrew/bin and /usr/local/bin. An attacker with write access to these…

  • CVE-2024-4031MedApr 23, 2024
    risk 0.29cvss 4.4epss 0.00

    Unquoted Search Path or Element vulnerability in Logitech MEVO WEBCAM APP on Windows allows Local Execution of Code.

  • CVE-2023-3438MedJul 3, 2023
    risk 0.29cvss 4.4epss 0.00

    An unquoted Windows search path vulnerability existed in the install the MOVE 4.10.x and earlier Windows install service (mvagtsce.exe). The misconfiguration allowed an unauthorized local user to insert arbitrary code into the unquoted service path to obtain privilege…

  • CVE-2021-25269MedNov 26, 2021
    risk 0.29cvss 4.4epss 0.00

    A local administrator could prevent the HMPA service from starting despite tamper protection using an unquoted service path vulnerability in the HMPA component of Sophos Intercept X Advanced and Sophos Intercept X Advanced for Server before version 2.0.23, as well as Sophos…

  • CVE-2020-35152MedFeb 3, 2021
    risk 0.29cvss 4.5epss 0.00

    Cloudflare WARP for Windows allows privilege escalation due to an unquoted service path. A malicious user or process running with non-administrative privileges can become an administrator by abusing the unquoted service path issue. Since version 1.2.2695.1, the vulnerability was…

  • CVE-2020-0507MedMar 12, 2020
    risk 0.29cvss 4.4epss 0.00

    Unquoted service path in Intel(R) Graphics Drivers before versions 15.33.49.5100, 15.36.38.5117, 15.40.44.5107, 15.45.30.5103, and 26.20.100.7212 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2020-1988MedApr 8, 2020
    risk 0.27cvss 4.2epss 0.00

    An unquoted search path vulnerability in the Windows release of Global Protect Agent allows an authenticated local user with file creation privileges on the root of the OS disk (C:\) or to Program Files directory to gain system privileges. This issue affects Palo Alto Networks…

  • CVE-2020-7252MedFeb 17, 2020
    risk 0.27cvss 4.2epss 0.01

    Unquoted service executable path in DXL Broker in McAfee Data eXchange Layer (DXL) Framework 6.0.0 and earlier allows local users to cause a denial of service and malicious file execution via carefully crafted and named executable files.