Falhas do tipo CWE-428

356 resultados

Caminho de busca sem aspas ou elemento desprotegido

Ocorre quando um programa busca executar um arquivo ou carregar uma biblioteca sem aspas no caminho, ou sem validar o local exato. Um atacante coloca um arquivo malicioso em um diretório anterior da busca, forçando o programa a executar o arquivo dele em vez do legítimo.

Exemplo

Um instalador Windows tenta executar 'C:\Program Files\Aplicacao\bin\tool.exe' sem aspas. Se o caminho contém espaço e o programa busca executáveis também em diretórios do sistema, um atacante cria 'C:\Program.exe' que será carregado antes.

Como mitigar

Use caminhos absolutos com aspas duplas em toda chamada de programa ou biblioteca (ex: '"C:\\Caminho Completo\\arquivo.exe"'). Valide e normalize todos os caminhos dinâmicos antes de usar, rejeitando qualquer que não corresponda exatamente ao esperado.

CVE-2026-9128HIGHStudio 5000 Logix Designer® – Multiple VulnerabilitiesEPSS 0.1%CVE-2025-10714HIGHAXIS Optimizer was vulnerable to an unquoted search path vulnerability, which could potentially lead to privilege escalation within MicrosofEPSS 0.1%CVE-2020-37223HIGHIObit Uninstaller 9.5.0.15 Unquoted Service Path Privilege EscalationEPSS 0.1%CVE-2020-37021HIGHBandwidth Monitor 3.9 - 'Svc10StrikeBandMontitor' Unquoted Service PathEPSS 0.1%CVE-2020-37101HIGHVPN unlimited 6.1 - Unquoted Service PathEPSS 0.1%CVE-2026-7280HIGHeMPIA Technology|AVACAST - Unquoted Service PathEPSS 0.1%CVE-2026-1585HIGHAn unquoted Windows service executable path vulnerability in IJ Scan Utility for Windows versions 1.1.2 through 1.5.0 may allow a local attaEPSS 0.1%CVE-2025-66269HIGHUnquoted Service Path in UPSilon2000V6.0(RupsMon and USBMate) running as SYSTEMEPSS 0.1%CVE-2025-66264HIGHUnquoted Service path in UPSilon2000V6.0 SYSTEM privilege serviceEPSS 0.1%CVE-2020-37232HIGHAdvanced System Care Service 13.0.0.157 Unquoted Service Path Privilege EscalationEPSS 0.1%CVE-2020-37247HIGHKite 4.2.0.1 U1 Unquoted Service Path Privilege EscalationEPSS 0.1%CVE-2020-37229HIGHOKI sPSV Port Manager 1.0.41 Unquoted Service Path Privilege EscalationEPSS 0.1%CVE-2020-37230HIGHSyncplify.me Server! 5.0.37 Unquoted Service Path Privilege EscalationEPSS 0.1%CVE-2025-32449MEDIUMUnquoted search path for some PRI Driver software before version 03.03.1002 within Ring 3: User Applications may allow an escalation of privEPSS 0.1%CVE-2021-47945HIGHArgus Surveillance DVR 4.0 Unquoted Service Path Privilege EscalationEPSS 0.1%CVE-2026-15358HIGHPath Traversal VulnerabilityEPSS