VYPR

CWE-428

Unquoted Search Path or Element

BaseDraft

Description

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

If a malicious individual has access to the file system, it is possible to elevate privileges by inserting such a file as "C:\Program.exe" to be run by a privileged program making use of WinExec.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (454)

page 8 of 23
  • CVE-2020-36992HigJan 28, 2026
    risk 0.51cvss 7.8epss 0.00

    Nord VPN 6.31.13.0 contains an unquoted service path vulnerability in its nordvpn-service that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted binary path during system startup or reboot to potentially run malicious code with…

  • CVE-2020-36991HigJan 28, 2026
    risk 0.51cvss 7.8epss 0.00

    ShareMouse 5.0.43 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the insecure service path configuration by placing malicious executables in specific system…

  • CVE-2020-36990HigJan 28, 2026
    risk 0.51cvss 7.8epss 0.00

    Input Director 1.4.3 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path during system startup or reboot to inject and run malicious…

  • CVE-2020-36989HigJan 28, 2026
    risk 0.51cvss 7.8epss 0.00

    ForensiT AppX Management Service 2.2.0.4 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code…

  • CVE-2020-36987HigJan 28, 2026
    risk 0.51cvss 7.8epss 0.00

    Program Access Controller 1.2.0.0 contains an unquoted service path vulnerability in PACService.exe that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path during system startup or reboot to inject and run malicious…

  • CVE-2020-36986HigJan 28, 2026
    risk 0.51cvss 7.8epss 0.00

    Prey 1.9.6 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in the CronService to insert malicious code that would execute during application startup or system…

  • CVE-2020-36985HigJan 28, 2026
    risk 0.51cvss 7.8epss 0.00

    IP Watcher 3.0.0.30 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with elevated…

  • CVE-2020-36984HigJan 28, 2026
    risk 0.51cvss 7.8epss 0.00

    EPSON 1.124 contains an unquoted service path vulnerability in the SENADB service that allows local attackers to execute code with elevated system privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\EPSON_P2B\Printer Software\Status Monitor\ to inject…

  • CVE-2020-36983HigJan 27, 2026
    risk 0.51cvss 7.8epss 0.00

    Quick 'n Easy FTP Service 3.2 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code during service startup. Attackers can exploit the misconfigured service binary path to inject malicious executables with elevated LocalSystem…

  • CVE-2020-36982HigJan 27, 2026
    risk 0.51cvss 7.8epss 0.00

    Motorola Device Manager 2.5.4 contains an unquoted service path vulnerability in the MotoHelperService.exe service that allows local users to potentially inject malicious code. Attackers can exploit the unquoted path in the service configuration to execute arbitrary code with…

  • CVE-2020-36981HigJan 27, 2026
    risk 0.51cvss 7.8epss 0.00

    Motorola Device Manager 2.4.5 contains an unquoted service path vulnerability in the PST Service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in ForwardDaemon.exe to inject malicious code that will execute with elevated…

  • CVE-2020-36980HigJan 27, 2026
    risk 0.51cvss 7.8epss 0.00

    SAntivirus IC 10.0.21.61 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted executable path to inject malicious files in the service binary…

  • CVE-2020-36979HigJan 27, 2026
    risk 0.51cvss 7.8epss 0.00

    Atheros Coex Service Application 8.0.0.255 contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path by placing malicious executables in the service path to gain elevated system privileges during service startup.

  • CVE-2020-36977HigJan 27, 2026
    risk 0.51cvss 7.8epss 0.00

    Wondershare Driver Install Service contains an unquoted service path vulnerability in the ElevationService executable that allows local attackers to potentially inject malicious code. Attackers can exploit the unquoted path to replace the service binary with a malicious…

  • CVE-2020-36976HigJan 27, 2026
    risk 0.51cvss 7.8epss 0.00

    Acer Global Registration Service 1.0.0.3 contains an unquoted service path vulnerability in its service configuration that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Acer\Registration\ to inject…

  • CVE-2020-36975HigJan 27, 2026
    risk 0.51cvss 7.8epss 0.00

    EPSON Status Monitor 3 version 8.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code by exploiting the service binary path. Attackers can leverage the unquoted path in 'C:\Program Files\Common…

  • CVE-2020-36974HigJan 27, 2026
    risk 0.51cvss 7.8epss 0.00

    Realtek Andrea RT Filters 1.0.64.7 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in 'C:\Program Files\IDT\WDM\AESTSr64.exe' to inject…

  • CVE-2020-36959HigJan 26, 2026
    risk 0.51cvss 7.8epss 0.00

    IDT PC Audio 1.0.6499.0 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the STacSV service to inject malicious code that would execute with…

  • CVE-2020-36958HigJan 26, 2026
    risk 0.51cvss 7.8epss 0.00

    Kite 1.2020.1119.0 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Kite\KiteService.exe' to inject malicious…

  • CVE-2020-36957HigJan 26, 2026
    risk 0.51cvss 7.8epss 0.00

    PDF Complete 3.5.310.2002 contains an unquoted service path vulnerability in its pdfsvc.exe service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with elevated LocalSystem privileges.