Weaknesses of type CWE-428

356 results

Caminho de busca ou elemento sem aspas

Ocorre quando o código procura executar um programa ou carregar uma biblioteca sem envolver o caminho em aspas, permitindo que espaços ou caracteres especiais no caminho sejam interpretados como separadores. Um atacante pode criar um executável em um diretório intermediário (ex: C:\Program Files\) e fazer com que o programa execute seu arquivo malicioso em vez do legítimo.

Example

Uma aplicação tenta chamar C:\Program Files\MyApp\tool.exe sem aspas. Se o Windows procura em C:\Program.exe primeiro (por causa do espaço), um atacante pode colocar um programa malicioso em C:\ com esse nome e ganhar execução de código.

How to mitigate

Sempre envolva caminhos completos em aspas duplas ("C:\\Program Files\\MyApp\\tool.exe") ou use APIs que aceitam argumentos separados (sem passar por shell parsing). Valide e normalize caminhos antes de usá-los.

CVE-2025-66461HIGHFULLBACK Manager Pro provided by GS Yuasa International Ltd. registers two Windows services with unquoted file paths. A user may execute arEPSS 0.2%CVE-2022-50920HIGHSandboxie-Plus 5.50.2 - 'Service SbieSvc' Unquoted Service PathEPSS 0.2%CVE-2022-50904HIGHWondershare UBackit 2.0.5 - 'wsbackup' Unquoted Service PathEPSS 0.2%CVE-2022-50913HIGHTCQ - 'ITeCProteccioAppServer.exe' Unquoted Service PathEPSS 0.2%CVE-2019-25231HIGHdevolo dLAN Cockpit 4.3.1 Unquoted Service Path Privilege EscalationEPSS 0.2%CVE-2016-20060HIGHHotspot Shield 6.0.3 Unquoted Service Path Privilege EscalationEPSS 0.2%CVE-2025-5191HIGHUnquoted Search Path Vulnerability in the Utility for Industrial Computers (Windows)EPSS 0.1%CVE-2020-24682HIGHAutomation Studio and PVI Multiple unquoted service path vulnerabilitiesEPSS 0.1%CVE-2026-57223HIGHSuricata windows: unquoted LocalSystem service ImagePath can allow local privilege escalationEPSS 0.1%CVE-2021-47869HIGHBRAdmin Professional 3.75 - 'BRA_Scheduler' Unquoted Service PathEPSS 0.1%CVE-2021-47886HIGHPingzapper 2.3.1 - 'PingzapperSvc' Unquoted Service PathEPSS 0.1%CVE-2025-9818MEDIUMVulnerability caused by unquoted file paths of Windows services registered by the Uninterruptible Power Supply (UPS) management applicationEPSS 0.1%CVE-2021-47867HIGHWIN-PACK PRO 4.8 - 'ScheduleService' Unquoted Service PathEPSS 0.1%CVE-2021-47862HIGHHi-Rez Studios 5.1.6.3 - 'HiPatchService' Unquoted Service PathEPSS 0.1%CVE-2021-47887HIGHPrint Job Accounting 4.4.10 - 'OkiJaSvc' Unquoted Service PathEPSS 0.1%CVE-2021-47878HIGHeBeam Education Suite 2.5.0.9 - 'eBeam Device Service' Unquoted Service PathEPSS 0.1%CVE-2021-47879HIGHeBeam Interactive Suite 3.6 - 'eBeam Stylus Driver' Unquoted Service PathEPSS 0.1%CVE-2021-47883HIGHSandboxie Plus v0.7.2 - 'SbieSvc' Unquoted Service PathEPSS 0.1%CVE-2021-47861HIGHEvent Log Explorer 4.9.3 - 'ElodeaEventCollectorService' Unquoted Service PathEPSS 0.1%CVE-2021-47864HIGHOSAS Traverse Extension 11 - 'travextensionhostsvc' Unquoted Service PathEPSS 0.1%