Fallos del tipo CWE-428

356 resultados

Caminho de busca sem aspas ou elemento não delimitado

Ocorre quando um aplicativo executa um programa ou carrega uma biblioteca usando um caminho sem aspas ou delimitação adequada, permitindo que espaços ou caracteres especiais no caminho sejam interpretados como separadores. Um atacante pode explorar isso colocando um executável malicioso em um diretório com nome parcial que coincida com a busca (ex: 'C:\Program Files\' interpretado como 'C:\Program\'), fazendo o sistema executar código não autorizado.

Ejemplo

Um serviço Windows tenta executar 'C:\Program Files\MeuApp\service.exe' mas o caminho não está entre aspas. O sistema busca primeiro por 'C:\Program.exe', depois 'C:\Program Files\MeuApp\service.exe'. Um atacante cria 'C:\Program.exe' malicioso e consegue executá-lo com privilégios do serviço.

Cómo mitigar

Sempre delimite caminhos com aspas duplas ao executar programas ou carregar bibliotecas dinâmicas. Use APIs que validem caminhos explicitamente, evite concatenação de strings para construir paths, e mantenha diretórios sensíveis com permissões restritivas para impedir criação de arquivos não autorizados.

CVE-2023-53984HIGHHotKey Clipboard 2.1.0.6 - Privilege Escalation Unquoted Service PathEPSS 0.2%CVE-2019-19705HIGHRealtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG bEPSS 0.2%CVE-2024-34010HIGHLocal privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber Protect Cloud AgentEPSS 0.2%CVE-2022-50933HIGHCain & Abel 4.9.56 - Unquoted Service PathEPSS 0.2%CVE-2025-21107HIGHDell NetWorker, version(s) prior to 19.11.0.3, all versions of 19.10 & prior versions contain(s) an Unquoted Search Path or Element vulnerabEPSS 0.2%CVE-2023-22282HIGHWAB-MAT Ver.5.0.0.8 and earlier starts another program with an unquoted file path. Since a registered Windows service path contains spaces aEPSS 0.2%CVE-2020-37100HIGHSync Breeze Enterprise 12.4.18 - Unquoted Service PathEPSS 0.2%CVE-2026-25865HIGHPunto Switcher 4.5.0.583 Unquoted Search Path via WinExecEPSS 0.2%CVE-2023-32658MEDIUMUnquoted search path in some Intel(R) NUC Kits NUC7i3DN, NUC7i5DN, NUC7i7DN HDMI firmware update tool software before version 1.79.1.1 may aEPSS 0.2%CVE-2016-20094HIGHAnyDesk 2.5.0 Unquoted Service Path Elevation of PrivilegeEPSS 0.2%CVE-2019-25276HIGHStudio 5000 Logix Designer 30.01.00 - 'FactoryTalk Activation Service' Unquoted Service PathEPSS 0.2%CVE-2023-0887HIGHphjounin TFTPD64-SE tftpd64_svc.exe unquoted search pathEPSS 0.2%CVE-2023-29165MEDIUMUnquoted search path or element in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to poteEPSS 0.2%CVE-2022-50918HIGHVIVE Runtime Service - 'ViveAgentService' Unquoted Service PathEPSS 0.2%CVE-2022-50938HIGHCONTPAQi® AdminPAQ 14.0.0 - Unquoted Service PathEPSS 0.2%CVE-2024-1201HIGHPanteraSoft HDD Health search path or unquoted item vulnerabilityEPSS 0.2%CVE-2022-50693HIGHSplashtop 8.71.12001.0 - Unquoted Service PathEPSS 0.2%CVE-2022-50929HIGHConnectify Hotspot 2018 'ConnectifyService' - Unquoted Service PathEPSS 0.2%CVE-2020-36977HIGHWondershare Driver Install Service help 10.7.1.321 - 'ElevationService' Unquote Service PathEPSS 0.2%CVE-2022-27592MEDIUMQVR Smart ClientEPSS 0.2%