Falhas do tipo CWE-428

356 resultados

Caminho de busca sem aspas ou elemento desprotegido

Ocorre quando um programa busca executar um arquivo ou carregar uma biblioteca sem aspas no caminho, ou sem validar o local exato. Um atacante coloca um arquivo malicioso em um diretório anterior da busca, forçando o programa a executar o arquivo dele em vez do legítimo.

Exemplo

Um instalador Windows tenta executar 'C:\Program Files\Aplicacao\bin\tool.exe' sem aspas. Se o caminho contém espaço e o programa busca executáveis também em diretórios do sistema, um atacante cria 'C:\Program.exe' que será carregado antes.

Como mitigar

Use caminhos absolutos com aspas duplas em toda chamada de programa ou biblioteca (ex: '"C:\\Caminho Completo\\arquivo.exe"'). Valide e normalize todos os caminhos dinâmicos antes de usar, rejeitando qualquer que não corresponda exatamente ao esperado.

CVE-2022-50917HIGHProtonVPN 1.26.0 - Unquoted Service PathEPSS 0.2%CVE-2024-58315HIGHTosibox Key Service 3.3.0 Local Privilege Escalation via Unquoted Service PathEPSS 0.2%CVE-2022-50915HIGHPTPublisher 2.3.4 - Unquoted Service PathEPSS 0.2%CVE-2023-54331HIGHOutline 1.6.0 - Unquoted Service PathEPSS 0.2%CVE-2025-0035HIGHUnquoted search path within AMD Cloud Manageability Service can allow a local attacker to escalate privileges, potentially resulting in arbiEPSS 0.2%CVE-2024-36321HIGHUnquoted search path within AIM-T Manageability Service can allow a local attacker to escalate privileges, potentially resulting in arbitrarEPSS 0.2%CVE-2022-35292In SAP Business One application when a service is created, the executable path contains spaces and isn’t enclosed within quotes, leading to EPSS 0.2%CVE-2024-31226MEDIUMSunshine's unquoted executable path could lead to hijacked execution flowEPSS 0.2%CVE-2022-50921HIGHWOW21 5.0.1.9 - 'Service WOW21_Service' Unquoted Service PathEPSS 0.2%CVE-2022-50928HIGHBluetooth Application 5.4.277 - 'BlueSoleilCS' Unquoted Service PathEPSS 0.2%CVE-2023-3842HIGHPointware EasyInventory Easy2W.exe unquoted search pathEPSS 0.2%CVE-2022-33920HIGHDell GeoDrive, versions prior to 2.2, contains an Unquoted File Path vulnerability. A low privilege attacker could potentially exploit this EPSS 0.2%CVE-2022-50924HIGHPrivate Internet Access 3.3 - 'pia-service' Unquoted Service PathEPSS 0.2%CVE-2022-4258HIGHHima: Unquoted path vulnerabilities in HIMA PC based SoftwareEPSS 0.2%CVE-2023-0392LOWThe LDAP Agent Update service with versions prior to 5.18 used an unquoted path, which could allow arbitrary code execution.EPSS 0.2%CVE-2022-50914HIGHEaseUS Data Recovery - 'ensserver.exe' Unquoted Service PathEPSS 0.2%CVE-2023-5012MEDIUMTopaz OFD Protection Module Warsaw core.exe unquoted search pathEPSS 0.2%CVE-2023-2644MEDIUMDigitalPersona FPSensor DpHost.exe unquoted search pathEPSS 0.2%CVE-2024-6080HIGHIntelbras InControl incontrolWebcam Service unquoted search pathEPSS 0.2%CVE-2025-57714HIGHNetBak ReplicatorEPSS 0.2%