Falhas do tipo CWE-428

356 resultados

Caminho de busca sem aspas ou elemento desprotegido

Ocorre quando um programa busca executar um arquivo ou carregar uma biblioteca sem aspas no caminho, ou sem validar o local exato. Um atacante coloca um arquivo malicioso em um diretório anterior da busca, forçando o programa a executar o arquivo dele em vez do legítimo.

Exemplo

Um instalador Windows tenta executar 'C:\Program Files\Aplicacao\bin\tool.exe' sem aspas. Se o caminho contém espaço e o programa busca executáveis também em diretórios do sistema, um atacante cria 'C:\Program.exe' que será carregado antes.

Como mitigar

Use caminhos absolutos com aspas duplas em toda chamada de programa ou biblioteca (ex: '"C:\\Caminho Completo\\arquivo.exe"'). Valide e normalize todos os caminhos dinâmicos antes de usar, rejeitando qualquer que não corresponda exatamente ao esperado.

CVE-2025-66461HIGHFULLBACK Manager Pro provided by GS Yuasa International Ltd. registers two Windows services with unquoted file paths. A user may execute arEPSS 0.2%CVE-2022-50904HIGHWondershare UBackit 2.0.5 - 'wsbackup' Unquoted Service PathEPSS 0.2%CVE-2022-50920HIGHSandboxie-Plus 5.50.2 - 'Service SbieSvc' Unquoted Service PathEPSS 0.2%CVE-2022-50913HIGHTCQ - 'ITeCProteccioAppServer.exe' Unquoted Service PathEPSS 0.2%CVE-2019-25231HIGHdevolo dLAN Cockpit 4.3.1 Unquoted Service Path Privilege EscalationEPSS 0.2%CVE-2016-20060HIGHHotspot Shield 6.0.3 Unquoted Service Path Privilege EscalationEPSS 0.2%CVE-2025-5191HIGHUnquoted Search Path Vulnerability in the Utility for Industrial Computers (Windows)EPSS 0.1%CVE-2025-9818MEDIUMVulnerability caused by unquoted file paths of Windows services registered by the Uninterruptible Power Supply (UPS) management applicationEPSS 0.1%CVE-2020-24682HIGHAutomation Studio and PVI Multiple unquoted service path vulnerabilitiesEPSS 0.1%CVE-2021-47886HIGHPingzapper 2.3.1 - 'PingzapperSvc' Unquoted Service PathEPSS 0.1%CVE-2026-57223HIGHSuricata windows: unquoted LocalSystem service ImagePath can allow local privilege escalationEPSS 0.1%CVE-2021-47869HIGHBRAdmin Professional 3.75 - 'BRA_Scheduler' Unquoted Service PathEPSS 0.1%CVE-2021-47862HIGHHi-Rez Studios 5.1.6.3 - 'HiPatchService' Unquoted Service PathEPSS 0.1%CVE-2020-36957HIGHPDF Complete 3.5.310.2002 - 'pdfsvc.exe' Unquoted Service PathEPSS 0.1%CVE-2021-47864HIGHOSAS Traverse Extension 11 - 'travextensionhostsvc' Unquoted Service PathEPSS 0.1%CVE-2021-47883HIGHSandboxie Plus v0.7.2 - 'SbieSvc' Unquoted Service PathEPSS 0.1%CVE-2021-47859HIGHActivIdentity 8.2 - 'ac.sharedstore' Unquoted Service PathEPSS 0.1%CVE-2021-47887HIGHPrint Job Accounting 4.4.10 - 'OkiJaSvc' Unquoted Service PathEPSS 0.1%CVE-2021-47863HIGHMacPaw Encrypto 1.0.1 - 'Encrypto Service' Unquoted Service PathEPSS 0.1%CVE-2021-47880HIGHRealtek Wireless LAN Utility 700.1631 - 'Realtek11nSU' Unquoted Service PathEPSS 0.1%