CWE-428— Unquoted Search Path or Element
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.— MITRE CWE catalog
456 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-428page 6 of 10
- CVE-2021-47845HIGHCVSS 7.8EG 7.82026-01-16
Spy Emergency 25.0.650 contains an unquoted service path vulnerability in its Windows service configurations that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted file paths in SpyEmergenc…
- CVE-2021-47847HIGHCVSS 7.8EG 7.82026-01-16
Disk Sorter Server 13.6.12 contains an unquoted service path vulnerability in its binary path configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Dis…
- CVE-2021-47859HIGHCVSS 7.8EG 7.82026-01-21
ActivIdentity 8.2 contains an unquoted service path vulnerability in the ac.sharedstore service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path in C:\Program Files\Common Fi…
- CVE-2021-47861HIGHCVSS 7.8EG 7.82026-01-21
Event Log Explorer 4.9.3 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path by placing malicious ex…
- CVE-2021-47862HIGHCVSS 7.8EG 7.82026-01-21
Hi-Rez Studios 5.1.6.3 contains an unquoted service path vulnerability in the HiPatchService that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path during system startup or reboot to i…
- CVE-2021-47863HIGHCVSS 7.8EG 7.82026-01-21
MacPaw Encrypto 1.0.1 contains an unquoted service path vulnerability in its Encrypto Service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files\Encr…
- CVE-2021-47864HIGHCVSS 7.8EG 7.82026-01-21
OSAS Traverse Extension 11 contains an unquoted service path vulnerability in the TravExtensionHostSvc service running with LocalSystem privileges. Attackers can exploit the unquoted path to inject and execute malicious code by placing exe…
- CVE-2021-47866HIGHCVSS 7.8EG 7.82026-01-21
WIN-PACK PRO 4.8 contains an unquoted service path vulnerability in the GuardTourService that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path in C:\Program Files <x86>…
- CVE-2021-47867HIGHCVSS 7.8EG 7.82026-01-21
WIN-PACK PRO4.8 contains an unquoted service path vulnerability in the ScheduleService that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path in 'C:\Program Files <x86>\…
- CVE-2021-47868HIGHCVSS 7.8EG 7.82026-01-21
WIN-PACK PRO 4.8 contains an unquoted service path vulnerability in the WPCommandFileService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files <x86>\WI…
- CVE-2021-47869HIGHCVSS 7.8EG 7.82026-01-21
Brother BRAdmin Professional 3.75 contains an unquoted service path vulnerability in the BRA_Scheduler service that allows local users to potentially execute arbitrary code. Attackers can place a malicious executable named 'BRAdmin' in the…
- CVE-2021-47874HIGHCVSS 7.8EG 7.82026-01-21
VFS for Git 1.0.21014.1 contains an unquoted service path vulnerability in the GVFS.Service Windows service that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted binary path to inject mali…
- CVE-2021-47878HIGHCVSS 7.8EG 7.82026-01-21
eBeam Education Suite 2.5.0.9 contains an unquoted service path vulnerability in the eBeam Device Service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in the service …
- CVE-2021-47879HIGHCVSS 7.8EG 7.82026-01-21
eBeam Interactive Suite 3.6 contains an unquoted service path vulnerability in the eBeam Stylus Driver service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Prog…
- CVE-2021-47880HIGHCVSS 7.8EG 7.82026-01-21
Realtek Wireless LAN Utility 700.1631 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted service path by inserting malicio…
- CVE-2021-47882HIGHCVSS 7.8EG 7.82026-01-21
FreeLAN 2.2 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that wil…
- CVE-2021-47883HIGHCVSS 7.8EG 7.82026-01-21
Sandboxie Plus 0.7.2 contains an unquoted service path vulnerability in the SbieSvc service that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted binary path to inject malicious executable…
- CVE-2021-47884HIGHCVSS 7.8EG 7.82026-01-21
OKI Configuration Tool 1.6.53 contains an unquoted service path vulnerability in the OKI Local Port Manager service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program F…
- CVE-2021-47886HIGHCVSS 7.8EG 7.82026-01-21
Pingzapper 2.3.1 contains an unquoted service path vulnerability in the PingzapperSvc service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Pingzapper\…
- CVE-2021-47887HIGHCVSS 7.8EG 7.82026-01-21
OKI Print Job Accounting 4.4.10 contains an unquoted service path vulnerability in the OkiJaSvc service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Okidata…
- CVE-2021-47889HIGHCVSS 7.8EG 7.82026-01-23
Softros LAN Messenger 9.6.4 contains an unquoted service path vulnerability in the SoftrosSpellChecker service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files …
- CVE-2021-47890HIGHCVSS 7.8EG 7.82026-01-23
LogonExpert 8.1 contains an unquoted service path vulnerability in the LogonExpertSvc service running with LocalSystem privileges. Attackers can exploit the unquoted path to place malicious executables in intermediate directories, potentia…
- CVE-2021-47896HIGHCVSS 7.8EG 7.82026-01-23
PDF Complete Corporate Edition 4.1.45 contains an unquoted service path vulnerability in the pdfcDispatcher service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in the service b…
- CVE-2021-47898HIGHCVSS 7.8EG 7.82026-01-23
Epson USB Display 1.6.0.0 contains an unquoted service path vulnerability in the EMP_UDSA service running with LocalSystem privileges. Attackers can exploit the unquoted path by placing malicious executables in intermediate directories to …
- CVE-2021-47945HIGHCVSS 7.8EG 7.82026-05-10
Argus Surveillance DVR 4.0 contains an unquoted service path vulnerability in the DVRWatchdog service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in t…
- CVE-2021-47974HIGHCVSS 7.8EG 7.82026-05-16
VX Search 13.5.28 contains an unquoted service path vulnerability in both VX Search Server and VX Search Enterprise services that allows local attackers to escalate privileges. Attackers can place malicious executables in unquoted path dir…
- CVE-2021-47985HIGHCVSS 7.8EG 7.82026-06-19
Brother SAPSprint 7.60 contains an unquoted service path vulnerability in the SAPSprint service binary that allows local attackers to escalate privileges. Attackers can place a malicious executable in the Program Files directory path to be…
- CVE-2022-0237HIGHCVSS 4.0EG 7.82022-03-17
Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execution due to an unquoted argument to the runas.exe command used by the ir_agent.exe compone…
- CVE-2022-0357MEDIUMCVSS 6.7EG 6.72023-05-24
Unquoted Search Path or Element vulnerability in the Vulnerability Scan component of Bitdefender Total Security, Bitdefender Internet Security, and Bitdefender Antivirus Plus allows an attacker to elevate privileges to SYSTEM. This issue …
- CVE-2022-0883HIGHCVSS 7.3EG 7.82022-05-18
SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.20.1 should be patched.
- CVE-2022-1697HIGHCVSS 3.9EG 7.82022-09-06
Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted path. Note: To remediate this vulnerability, you must uninstall Okta Active Directory Agent and reinstall Okta Active Di…
- CVE-2022-2147HIGHCVSS 6.5EG 7.82022-06-23
Cloudflare Warp for Windows from version 2022.2.95.0 contained an unquoted service path which enables arbitrary code execution leading to privilege escalation. The fix was released in version 2022.3.186.0.
- CVE-2022-23909HIGHCVSS 7.8EG 7.82022-04-05
There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might allow a local user to escalate privileges by creating a "C:\Program Files\Sherpa Software\Sherpa.exe" file.
- CVE-2022-25031HIGHCVSS 7.8EG 7.82022-03-03
Remote Desktop Commander Suite Agent before v4.8 contains an unquoted service path which allows attackers to escalate privileges to the system level.
- CVE-2022-26634HIGHCVSS 7.8EG 7.82022-05-20
HMA VPN v5.3.5913.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.
- CVE-2022-27050HIGHCVSS 7.8EG 7.82022-03-31
BitComet Service for Windows before version 1.8.6 contains an unquoted service path vulnerability which allows attackers to escalate privileges to the system level.
- CVE-2022-27052HIGHCVSS 7.8EG 7.82022-03-31
FreeFtpd version 1.0.13 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.
- CVE-2022-27088HIGHCVSS 7.8EG 7.82022-04-11
Ivanti DSM Remote <= 6.3.1.1862 is vulnerable to an unquoted service path allowing local users to launch processes with elevated privileges.
- CVE-2022-27089HIGHCVSS 7.8EG 7.82022-04-11
In Fujitsu PlugFree Network <= 7.3.0.3, an Unquoted service path in PFNService.exe software allows a local attacker to potentially escalate privileges to system level.
- CVE-2022-27094MEDIUMCVSS 6.7EG 6.72022-05-20
Sony PlayMemories Home v6.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.
- CVE-2022-27095HIGHCVSS 7.8EG 7.82022-05-20
BattlEye v0.9 contains an unquoted service path which allows attackers to escalate privileges to the system level.
- CVE-2022-27592MEDIUMCVSS 6.7EG 6.72024-09-06
An unquoted search path or element vulnerability has been reported to affect QVR Smart Client. If exploited, the vulnerability could allow local authenticated administrators to execute unauthorized code or commands via unspecified vectors.…
- CVE-2022-27905HIGHCVSS 7.2EG 7.22022-04-27
In ControlUp Real-Time Agent before 8.6, an unquoted path can result in privilege escalation. An attacker would require write permissions to the root level of the OS drive (C:\) to exploit this.
- CVE-2022-27963MEDIUMCVSS 6.5EG 6.52022-03-31
Xftp 7.0.0088p and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.
- CVE-2022-27964MEDIUMCVSS 6.5EG 6.52022-03-31
Xmanager v7.0.0096 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.
- CVE-2022-27965MEDIUMCVSS 6.5EG 6.52022-03-31
Xlpd v7.0.0094 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.
- CVE-2022-27966MEDIUMCVSS 6.5EG 6.52022-03-31
Xshell v7.0.0099 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.
- CVE-2022-29320HIGHCVSS 7.8EG 7.82022-05-20
MiniTool Partition Wizard v12.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.
- CVE-2022-31590HIGHCVSS 7.8EG 7.82022-06-14
SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to work around system’s root disk access restrictions to Write/Create a program file on system disk root path, which co…
- CVE-2022-31591HIGHCVSS 7.8EG 7.82022-07-12
SAP BusinessObjects BW Publisher Service - versions 420, 430, uses a search path that contains an unquoted element. A local attacker can gain elevated privileges by inserting an executable file in the path of the affected service
Map vulnerabilities like CWE-428 to your infrastructure
EchelonGraph correlates every CVE — across CWE-428 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →