Fallos del tipo CWE-428

355 resultados

Caminho de busca sem aspas ou elemento não delimitado

Ocorre quando um aplicativo executa um programa ou carrega uma biblioteca usando um caminho sem aspas ou delimitação adequada, permitindo que espaços ou caracteres especiais no caminho sejam interpretados como separadores. Um atacante pode explorar isso colocando um executável malicioso em um diretório com nome parcial que coincida com a busca (ex: 'C:\Program Files\' interpretado como 'C:\Program\'), fazendo o sistema executar código não autorizado.

Ejemplo

Um serviço Windows tenta executar 'C:\Program Files\MeuApp\service.exe' mas o caminho não está entre aspas. O sistema busca primeiro por 'C:\Program.exe', depois 'C:\Program Files\MeuApp\service.exe'. Um atacante cria 'C:\Program.exe' malicioso e consegue executá-lo com privilégios do serviço.

Cómo mitigar

Sempre delimite caminhos com aspas duplas ao executar programas ou carregar bibliotecas dinâmicas. Use APIs que validem caminhos explicitamente, evite concatenação de strings para construir paths, e mantenha diretórios sensíveis com permissões restritivas para impedir criação de arquivos não autorizados.

CVE-2024-58288HIGHGenexus Protection Server 9.7.2.10 Unquoted Service Path Privilege EscalationEPSS 0.4%CVE-2020-7581A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2EPSS 0.4%CVE-2020-8337An unquoted search path vulnerability was reported in versions prior to 1.0.83.0 of the Synaptics Smart Audio UWP app associated with the DCEPSS 0.4%CVE-2017-14030An issue was discovered in Moxa MXview v2.8 and prior. The unquoted service path escalation vulnerability could allow an authorized user witEPSS 0.4%CVE-2020-1988MEDIUMGlobal Protect Agent: Local privilege escalation due to an unquoted search path vulnerabilityEPSS 0.4%CVE-2020-8327HIGHA privilege escalation vulnerability was reported in LenovoBatteryGaugePackage for Lenovo System Interface Foundation bundled in Lenovo VantEPSS 0.4%CVE-2019-25269HIGHAmiti Antivirus 25.0.640 - Unquoted Service Path VulnerabilityEPSS 0.3%CVE-2019-25271HIGHNETGATE Data Backup 3.0.620 - 'NGDatBckpSrv' Unquoted Service PathEPSS 0.3%CVE-2023-2417MEDIUMks-soft Advanced Host Monitor rma_active.exe unquoted search pathEPSS 0.3%CVE-2024-9325HIGHIntelbras InControl incontrol-service-watchdog.exe unquoted search pathEPSS 0.3%CVE-2020-10051A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). Multiple services of the affected applicationEPSS 0.3%CVE-2025-39246MEDIUMThere is an Unquoted Service Path Vulnerability in some HikCentral FocSign versions. This could allow an authenticated user to potentially eEPSS 0.3%CVE-2021-23879MEDIUMUnquoted service path vulnerability in McAfee Endpoint Product Removal (EPR) Tool prior to 21.2 allows local administrators to execute arbitrary code, with higher-level privileges, via execution from a compromised folder. The tool did not enforce and ...EPSS 0.3%CVE-2025-4540HIGHMTSoftware C-Lodop CLodopPrintService unquoted search pathEPSS 0.3%CVE-2020-7275MEDIUMUnquoted service paths for some McAfee ENS filesEPSS 0.3%CVE-2021-47773HIGHDynojet Power Core 2.3.0 - Unquoted Service PathEPSS 0.3%CVE-2024-8975HIGHGrafana Alloy on Windows Unquoted service pathEPSS 0.3%CVE-2022-44264HIGHDentsply Sirona Sidexis <= 4.3 is vulnerable to Unquoted Service Path.EPSS 0.3%CVE-2020-7382MEDIUMUnquoted Path in Rapid7 Nexpose InstallerEPSS 0.3%CVE-2023-7043LOWUnquoted path privilege vulnerability in ESET products for WindowsEPSS 0.3%