Falhas do tipo CWE-428

354 resultados

Caminho de busca sem aspas ou elemento desprotegido

Ocorre quando um programa busca executar um arquivo ou carregar uma biblioteca sem aspas no caminho, ou sem validar o local exato. Um atacante coloca um arquivo malicioso em um diretório anterior da busca, forçando o programa a executar o arquivo dele em vez do legítimo.

Exemplo

Um instalador Windows tenta executar 'C:\Program Files\Aplicacao\bin\tool.exe' sem aspas. Se o caminho contém espaço e o programa busca executáveis também em diretórios do sistema, um atacante cria 'C:\Program.exe' que será carregado antes.

Como mitigar

Use caminhos absolutos com aspas duplas em toda chamada de programa ou biblioteca (ex: '"C:\\Caminho Completo\\arquivo.exe"'). Valide e normalize todos os caminhos dinâmicos antes de usar, rejeitando qualquer que não corresponda exatamente ao esperado.

CVE-2020-28209HIGHA CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and EnEPSS 0.3%CVE-2021-35231MEDIUMUnquoted Path (SMB Login) VulnerabilityEPSS 0.3%CVE-2020-35152MEDIUMPrivilege escalation through unquoted service binary path on Cloudflare WARP for WindowsEPSS 0.3%CVE-2024-3640HIGHRockwell Automation FactoryTalk® Remote Access™ has Unquoted ExecutablesEPSS 0.3%CVE-2021-23197MEDIUMUnquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the accountEPSS 0.3%CVE-2020-36879HIGHFlexsense DiskBoss Service Unquoted Service Path VulnerabilityEPSS 0.3%CVE-2024-8996HIGHGrafana Agent Flow on Windows Unquoted service pathEPSS 0.3%CVE-2022-2147MEDIUMUnquoted Service Path in Cloudflare WARP for WindowsEPSS 0.3%CVE-2022-50901HIGHWondershare Dr.Fone 11.4.9 - 'DFWSIDService' Unquoted Service PathEPSS 0.3%CVE-2022-50903HIGHWondershare MobileTrans 3.5.9 - 'ElevationService' Unquoted Service PathEPSS 0.3%CVE-2020-36928HIGHBrother BRAgent 1.38 - 'WBA_Agent_Client' Unquoted Service PathEPSS 0.3%CVE-2021-47787HIGHTotalAV 5.15.69 - Unquoted Service PathEPSS 0.3%CVE-2020-36929HIGHBrother BRPrint Auditor 3.0.7 - 'Multiple' Unquoted Service PathEPSS 0.3%CVE-2022-31591SAP BusinessObjects BW Publisher Service - versions 420, 430, uses a search path that contains an unquoted element. A local attacker can gaiEPSS 0.3%CVE-2021-47780HIGHMacro Expert 4.7 - Unquoted Service PathEPSS 0.3%CVE-2023-4991HIGHNextBX QWAlerter QWAlerter.exe unquoted search pathEPSS 0.2%CVE-2024-1618HIGHUnquoted item or search path vulnerability in Faronics Deep Freeze Server StandardEPSS 0.2%CVE-2022-31590SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to work around system’EPSS 0.2%CVE-2020-36930HIGHSysGauge 7.9.18 - ' SysGauge Server' Unquoted Service PathEPSS 0.2%CVE-2020-36927HIGHDiskPulse 13.6.14 - Unquoted Service PathEPSS 0.2%