Falhas do tipo CWE-428

356 resultados

Caminho de busca sem aspas ou elemento desprotegido

Ocorre quando um programa busca executar um arquivo ou carregar uma biblioteca sem aspas no caminho, ou sem validar o local exato. Um atacante coloca um arquivo malicioso em um diretório anterior da busca, forçando o programa a executar o arquivo dele em vez do legítimo.

Exemplo

Um instalador Windows tenta executar 'C:\Program Files\Aplicacao\bin\tool.exe' sem aspas. Se o caminho contém espaço e o programa busca executáveis também em diretórios do sistema, um atacante cria 'C:\Program.exe' que será carregado antes.

Como mitigar

Use caminhos absolutos com aspas duplas em toda chamada de programa ou biblioteca (ex: '"C:\\Caminho Completo\\arquivo.exe"'). Valide e normalize todos os caminhos dinâmicos antes de usar, rejeitando qualquer que não corresponda exatamente ao esperado.

CVE-2019-25287HIGHAdaware Web Companion version 4.8.2078.3950 - 'WCAssistantService' Unquoted Service PathEPSS 0.2%CVE-2020-37064HIGHEPSON EasyMP Network Projection 2.81 - 'EMP_NSWLSV' Unquoted Service PathEPSS 0.2%CVE-2020-37037HIGHAVAST SecureLine 5.5.522.0 - 'SecureLine' Unquoted Service PathEPSS 0.2%CVE-2019-25286HIGH_GCafé 3.0 - 'gbClienService' Unquoted Service PathEPSS 0.2%CVE-2025-8070CRITICALWindows service registered with an unquoted ImagePath vulnerability in the system registryEPSS 0.2%CVE-2025-12247HIGHHasleo Backup Suite HasleoImageMountService/HasleoBackupSuiteService unquoted search pathEPSS 0.2%CVE-2023-53946HIGHArcsoft PhotoStudio 6.0.0.172 Unquoted Service Path Privilege EscalationEPSS 0.2%CVE-2023-53947HIGHOCS Inventory NG 2.3.0.0 Unquoted Service Path Privilege EscalationEPSS 0.2%CVE-2020-37253HIGHWinstep 18.06.0096 Unquoted Service Path Privilege EscalationEPSS 0.2%CVE-2021-47828HIGHBOOTP Turbo 2.0.0.1253 - 'bootpt.exe' Unquoted Service PathEPSS 0.2%CVE-2019-25307HIGHWorkgroupMail 7.5.1 - 'WorkgroupMail' Unquoted Service PathEPSS 0.2%CVE-2019-25306HIGHBlackMoon FTP Server 3.1.2.1731 - 'BMFTP-RELEASE' Unquoted Serive PathEPSS 0.2%CVE-2019-25309HIGHZilab Remote Console Server 3.2.9 - 'Zilab Remote Console Server' Unquoted Service PathEPSS 0.2%CVE-2025-66461HIGHFULLBACK Manager Pro provided by GS Yuasa International Ltd. registers two Windows services with unquoted file paths. A user may execute arEPSS 0.2%CVE-2022-50930HIGHEmerson PAC Machine Edition 9.80 Build 8695 - 'TrapiServer' Unquoted Service PathEPSS 0.2%CVE-2025-0884HIGHPrivilege Escalation vulnerability has been discovered in OpenText™ Service Manager.EPSS 0.2%CVE-2016-20056HIGHSpy Emergency build 23.0.205 Unquoted Service Path Privilege EscalationEPSS 0.2%CVE-2025-66271HIGHClone for Windows provided by ELECOM CO.,LTD. registers a Windows service with an unquoted file path. A user with the write permission on thEPSS 0.2%CVE-2025-64151HIGHMultiple Roboticsware products provided by Roboticsware PTE. LTD. register Windows services with unquoted file paths. A user with the write EPSS 0.2%CVE-2025-62225HIGHOptical Disc Archive Software provided by Sony Corporation registers a Windows service with an unquoted file path. A user with the write perEPSS 0.2%