VYPR

CWE-428

Unquoted Search Path or Element

BaseDraft

Description

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

If a malicious individual has access to the file system, it is possible to elevate privileges by inserting such a file as "C:\Program.exe" to be run by a privileged program making use of WinExec.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (454)

page 5 of 23
  • CVE-2016-20061HigApr 4, 2026
    risk 0.51cvss 7.8epss 0.00

    sheed AntiVirus 2.3 contains an unquoted service path vulnerability in the ShavProt service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can insert a malicious executable in the unquoted path and trigger service restart or…

  • CVE-2016-20060HigApr 4, 2026
    risk 0.51cvss 7.8epss 0.00

    Hotspot Shield 6.0.3 contains an unquoted service path vulnerability in the hshld service binary that allows local attackers to escalate privileges by injecting malicious executables. Attackers can place executable files in the service path and upon service restart or system…

  • CVE-2016-20059HigApr 4, 2026
    risk 0.51cvss 7.8epss 0.00

    IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local attackers to escalate privileges. Attackers can insert a malicious executable file in the unquoted service path and trigger privilege…

  • CVE-2016-20058HigApr 4, 2026
    risk 0.51cvss 7.8epss 0.01

    Netgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnerability in the AmitiAvSrv and AmitiAntivirusHealth services that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted service path and trigger…

  • CVE-2016-20057HigApr 4, 2026
    risk 0.51cvss 7.8epss 0.01

    NETGATE Registry Cleaner build 16.0.205 contains an unquoted service path vulnerability in the NGRegClnSrv service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the unquoted path and…

  • CVE-2016-20056HigApr 4, 2026
    risk 0.51cvss 7.8epss 0.00

    Spy Emergency build 23.0.205 contains an unquoted service path vulnerability in the SpyEmrgHealth and SpyEmrgSrv services that allows local attackers to escalate privileges by inserting malicious executables. Attackers can place executable files in the unquoted service path and…

  • CVE-2016-20055HigApr 4, 2026
    risk 0.51cvss 7.8epss 0.00

    IObit Advanced SystemCare 10.0.2 contains an unquoted service path vulnerability in the AdvancedSystemCareService10 service that allows local attackers to escalate privileges. Attackers can place a malicious executable in the service path and trigger privilege escalation when…

  • CVE-2025-41359HigMar 26, 2026
    risk 0.51cvss 7.8epss 0.00

    Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable located at 'C:\Program Files (x86)\shttps_mg\http.exe service'. This misconfiguration allows a local attacker to place a malicious executable with the same name…

  • CVE-2017-20218HigMar 16, 2026
    risk 0.51cvss 7.8epss 0.00

    Serviio PRO 1.8 contains an unquoted search path vulnerability in the Windows service that allows local users to execute arbitrary code with elevated privileges by placing malicious executables in the system root path. Additionally, improper directory permissions with full…

  • CVE-2026-25866HigMar 9, 2026
    risk 0.51cvss 7.8epss 0.00

    MobaXterm versions prior to 26.1 contain an uncontrolled search path element vulnerability. The application calls WinExec to execute Notepad++ without a fully qualified executable path when opening remote files. An attacker can exploit the search path behavior by placing a…

  • CVE-2026-26034HigMar 5, 2026
    risk 0.51cvss 7.8epss 0.00

    UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Incorrect Default Permissions (CWE-276) vulnerability that allows an attacker to execute arbitrary code with SYSTEM privileges by causing the application to load a specially crafted DLL.

  • CVE-2019-25345HigFeb 12, 2026
    risk 0.51cvss 7.8epss 0.00

    Realtek IIS Codec Service 6.4.10041.133 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in the service configuration to inject malicious executables and escalate privileges…

  • CVE-2019-25310HigFeb 11, 2026
    risk 0.51cvss 7.8epss 0.00

    ActiveFax Server 6.92 Build 0316 contains an unquoted service path vulnerability in the ActiveFaxServiceNT service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be…

  • CVE-2019-25309HigFeb 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Zilab Remote Console Server 3.2.9 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious…

  • CVE-2019-25308HigFeb 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Mikogo 5.2.2.150317 contains an unquoted service path vulnerability in the Mikogo-Service Windows service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with LocalSystem privileges by placing executable files in specific path…

  • CVE-2019-25307HigFeb 11, 2026
    risk 0.51cvss 7.8epss 0.00

    WorkgroupMail 7.5.1 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with…

  • CVE-2019-25306HigFeb 11, 2026
    risk 0.51cvss 7.8epss 0.00

    BlackMoon FTP Server 3.1.2.1731 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to insert malicious code that would…

  • CVE-2019-25305HigFeb 6, 2026
    risk 0.51cvss 7.8epss 0.00

    JumpStart 0.6.0.0 contains an unquoted service path vulnerability in the jswpbapi service running with LocalSystem privileges. Attackers can exploit the unquoted path containing spaces to inject and execute malicious code with elevated system permissions.

  • CVE-2019-25304HigFeb 6, 2026
    risk 0.51cvss 7.8epss 0.00

    SecurOS Enterprise 10.2 contains an unquoted service path vulnerability in the SecurosCtrlService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\ISS\SecurOS\ to insert malicious code…

  • CVE-2019-25302HigFeb 6, 2026
    risk 0.51cvss 7.8epss 0.00

    Acer Launch Manager 6.1.7600.16385 contains an unquoted service path vulnerability in the DsiWMIService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Launch Manager\dsiwmis.exe to…