Weaknesses of type CWE-428

356 results

Caminho de busca ou elemento sem aspas

Ocorre quando o código procura executar um programa ou carregar uma biblioteca sem envolver o caminho em aspas, permitindo que espaços ou caracteres especiais no caminho sejam interpretados como separadores. Um atacante pode criar um executável em um diretório intermediário (ex: C:\Program Files\) e fazer com que o programa execute seu arquivo malicioso em vez do legítimo.

Example

Uma aplicação tenta chamar C:\Program Files\MyApp\tool.exe sem aspas. Se o Windows procura em C:\Program.exe primeiro (por causa do espaço), um atacante pode colocar um programa malicioso em C:\ com esse nome e ganhar execução de código.

How to mitigate

Sempre envolva caminhos completos em aspas duplas ("C:\\Program Files\\MyApp\\tool.exe") ou use APIs que aceitam argumentos separados (sem passar por shell parsing). Valide e normalize caminhos antes de usá-los.

CVE-2020-37223HIGHIObit Uninstaller 9.5.0.15 Unquoted Service Path Privilege EscalationEPSS 0.1%CVE-2026-9128HIGHStudio 5000 Logix Designer® – Multiple VulnerabilitiesEPSS 0.1%CVE-2020-37231HIGHPrivacy Drive 3.17.0 Unquoted Service Path Privilege EscalationEPSS 0.1%CVE-2020-37021HIGHBandwidth Monitor 3.9 - 'Svc10StrikeBandMontitor' Unquoted Service PathEPSS 0.1%CVE-2026-7280HIGHeMPIA Technology|AVACAST - Unquoted Service PathEPSS 0.1%CVE-2020-37101HIGHVPN unlimited 6.1 - Unquoted Service PathEPSS 0.1%CVE-2026-1585HIGHAn unquoted Windows service executable path vulnerability in IJ Scan Utility for Windows versions 1.1.2 through 1.5.0 may allow a local attaEPSS 0.1%CVE-2025-66264HIGHUnquoted Service path in UPSilon2000V6.0 SYSTEM privilege serviceEPSS 0.1%CVE-2025-66269HIGHUnquoted Service Path in UPSilon2000V6.0(RupsMon and USBMate) running as SYSTEMEPSS 0.1%CVE-2020-37232HIGHAdvanced System Care Service 13.0.0.157 Unquoted Service Path Privilege EscalationEPSS 0.1%CVE-2020-37247HIGHKite 4.2.0.1 U1 Unquoted Service Path Privilege EscalationEPSS 0.1%CVE-2020-37229HIGHOKI sPSV Port Manager 1.0.41 Unquoted Service Path Privilege EscalationEPSS 0.1%CVE-2020-37230HIGHSyncplify.me Server! 5.0.37 Unquoted Service Path Privilege EscalationEPSS 0.1%CVE-2025-32449MEDIUMUnquoted search path for some PRI Driver software before version 03.03.1002 within Ring 3: User Applications may allow an escalation of privEPSS 0.1%CVE-2021-47945HIGHArgus Surveillance DVR 4.0 Unquoted Service Path Privilege EscalationEPSS 0.1%CVE-2026-15358HIGHPath Traversal VulnerabilityEPSS