AVACAST developed by eMPIA Technology has a Unquoted Service Path vulnerability, allowing privileged local attackers to
NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerabil
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version
The HP Fan Control App might allow local escalation of privileges. An updated version of HP Fan Control App has been rel
The service Bizerba Communication Server (BCS) has an unquoted service path. Due to the way Windows searches the executa
AXIS Optimizer was vulnerable to an unquoted search path vulnerability, which could potentially lead to privilege escala
Arcsoft PhotoStudio 6.0.0.172 contains an unquoted service path vulnerability in the ArcSoft Exchange Service that allow
OCS Inventory NG 2.3.0.0 contains an unquoted service path vulnerability that allows local attackers to escalate privile
Cobian Backup Gravity 11.2.0.582 contains an unquoted service path vulnerability that allows local users to potentially
SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to
Epic Games Easy Anti-Cheat 4.0 contains an unquoted service path vulnerability that allows local non-privileged users to
Selea CarPlateServer 4.0.1.6 contains an unquoted service path vulnerability in the Windows service configuration that a
Dell NetWorker, version(s) prior to 19.11.0.3, all versions of 19.10 & prior versions contain(s) an Unquoted Search Path
A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely prior ver
Dell Wireless 5932e and Qualcomm Snapdragon X62 Firmware and GNSS/GPS Driver, versions prior to 3.2.0.22 contain an Unqu
An unquoted search path or element vulnerability has been reported to affect NetBak Replicator. If a local attacker gain
An unquoted service path in Kingosoft Technology Ltd Kingo ROOT v1.5.8.3353 allows attackers to escalate privileges via
VeeVPN 1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute
Tosibox Key Service 3.3.0 contains an unquoted service path vulnerability that allows local non-privileged users to pote
In Electronic Arts Dragon Age Origins 1.05, the DAUpdaterSVC service contains an unquoted service path vulnerability. Th
Unquoted search path within AIM-T Manageability Service can allow a local attacker to escalate privileges, potentially r
Unquoted search path within AMD Cloud Manageability Service can allow a local attacker to escalate privileges, potential
Unquoted Search Path or Element vulnerability in NetBT Consulting Services Inc. E-Fatura allows Leveraging/Manipulating
A vulnerability was found in MTSoftware C-Lodop 6.6.1.1 on Windows. It has been rated as critical. This issue affects so
A weakness has been identified in Hasleo Backup Suite up to 5.2. Impacted is an unknown function of the component Hasleo
A weakness has been identified in VeePN up to 1.6.2. This affects an unknown function of the file C:\Program Files (x86)
A security flaw has been discovered in Muse Group MuseHub 2.1.0.1567. The affected element is an unknown function of the
Western Digital Kitfox for Windows provided by Western Digital Corporation registers a Windows service with an unquoted
RATOC RAID Monitoring Manager for Windows provided by RATOC Systems, Inc. registers a Windows service with an unquoted f
RAID Manager provided by Century Corporation registers a Windows service with an unquoted file path. A user with the wri
A vulnerability (CWE-428) has been identified in the Uninterruptible Power Supply (UPS) management application provided
Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineS
NAS Navigator2 Windows version by BUFFALO INC. registers a Windows service with an unquoted file path. A user with the w
Multiple NAS management applications provided by I-O DATA DEVICE, INC. register Windows services with unquoted file path
memoQ 10.1.13.ef1b2b52aae and earlier contains an unquoted service path vulnerability in the memoQ Auto Update Service (
Optical Disc Archive Software provided by Sony Corporation registers a Windows service with an unquoted file path. A use
Multiple Roboticsware products provided by Roboticsware PTE. LTD. register Windows services with unquoted file paths. A
Unquoted search path for some PRI Driver software before version 03.03.1002 within Ring 3: User Applications may allow a
FULLBACK Manager Pro provided by GS Yuasa International Ltd. registers two Windows services with unquoted file paths. A
Clone for Windows provided by ELECOM CO.,LTD. registers a Windows service with an unquoted file path. A user with the wr
Improper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution
Local privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber
USB Flash Drives Control 4.1.0.0 contains an unquoted service path vulnerability in its service configuration that allow
ActFax 10.10 contains an unquoted service path vulnerability that allows local attackers to potentially escalate privile
There is an Unquoted Service Path Vulnerability in some HikCentral FocSign versions. This could allow an authenticated u
Xerox Desktop Print Experience application contains a Local Privilege Escalation (LPE) vulnerability, which allows a low
Unquoted Search Path or Element vulnerability in OpenText™ Service Manager. The vulnerability could allow a user to ga
The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability. This allow
The service executable path in Seagate Toolkit on Versions prior to 2.34.0.33 on Windows allows an attacker with Admin p
An Unquoted Search Path vulnerability has been identified in the utility for Moxa’s industrial computers (Windows). Due
Frequently Asked Questions
What is CWE-428?
CWE-428 (CWE-428) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-428?
There are 510 CVE records associated with CWE-428 in our database. Of these, 7 are critical severity, 337 are high severity, and 89 are medium severity.
How can I protect against CWE-428 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-428 using AI-powered security agents.
Detect CWE-428 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-428 vulnerabilities across your infrastructure.
Get Started