The CMService.exe service runs with SYSTEM privileges and contains an unquoted service path. This allows a local attacke
The RupsMon and USBMate services in UPSilon 2000 run with SYSTEM privileges and contain unquoted service paths. This all
Flexsense DiskBoss 11.7.28 allows unauthenticated attackers to elevate their privileges using any of its services, enabl
Genexus Protection Server 9.7.2.10 contains an unquoted service path vulnerability in the protsrvservice Windows service
AnyDesk 7.0.15 and 9.0.1 contains an unquoted service path vulnerability that allows local non-privileged users to poten
An unquoted service path vulnerability in the 12d Synergy Server and File Replication Server components may allow an att
Local privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber
PowerSYSTEM Center versions 2020 Update 16 and prior contain a vulnerability that may allow an authorized local user to
Search path or unquoted item vulnerability in HDD Health affecting versions 4.2.0.112 and earlier. This vulnerability co
A local attacker can gain administrative privileges by inserting an executable file in the path of the affected product.
A search path or unquoted item vulnerability in Faronics Deep Freeze Server Standard, which affects versions 8.30.020.46
Unquoted path or search item vulnerability in SugarSync versions prior to 4.1.3 for Windows. This misconfiguration could
CWE-428: Unquoted search path or element vulnerability exists in Easergy Studio, which could cause privilege escalation
A vulnerability classified as critical was found in Intelbras InControl 2.21.56. This vulnerability affects unknown code
Unquoted Search Path or Element vulnerability in ABB Mint Workbench. A local attacker who successfully exploited this
Windows Setup and Deployment Elevation of Privilege Vulnerability
A vulnerability classified as critical has been found in Intelbras InControl up to 2.21.56. This affects an unknown part
A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual en
A potential security vulnerability has been identified in VSS Provider and CAPI Proxy software for certain HPE MSA stor
Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to
Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from L
Unquoted Search Path or Element vulnerability in B&R Industrial Automation Automation Studio, B&R Industrial Automation
Triangle MicroWorks SCADA Data Gateway GTWWebMonitorService Unquoted Search Path Remote Code Execution Vulnerability. Th
Unquoted search path or element in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an
An unquoted service path vulnerability in Terratec DMX_6Fire USB v.1.23.0.02 allows a local attacker to escalate privile
Unquoted Executable Path vulnerability in Hitachi Device Manager on Windows (Device Manager Server component).This issue
An unquoted search path or element vulnerability has been reported to affect QVR Smart Client. If exploited, the vulnera
A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service. Such misconfiguration could be
Sunshine is a self-hosted game stream host for Moonlight. Users who ran Sunshine versions 0.17.0 through 0.22.2 as a ser
Unquoted Search Path or Element vulnerability in Logitech MEVO WEBCAM APP on Windows allows Local Execution of Code.
Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with t
An unquoted executable path exists in the Rockwell Automation FactoryTalk® Remote Access™ possibly resulting in remote c
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
Uncontrolled search path in the WULT software maintained by Intel(R) before version 1.0.0 (commit id 592300b) may allow
In multiple versions of HIMA PC based Software an unquoted Windows search path vulnerability might allow local users to
Dentsply Sirona Sidexis <= 4.3 is vulnerable to Unquoted Service Path.
Dell Multifunction Printer E525w Driver and Software Suite, versions prior to 1.047.2022, A05, contain a local privileg
VX Search v13.8 and v14.7 was discovered to contain an unquoted service path vulnerability which allows attackers to exe
Unquoted service Path or Element vulnerability in 42Gears Surelock Windows SureLock Service (NixService.Exe) on Windows
Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the comp
A vulnerability was found in Pointware EasyInventory 1.0.12.0 and classified as critical. This issue affects some unknow
ASUS SetupAsusServices v1.0.5.1 in Asus Armoury Crate v5.3.4.0 contains an unquoted service path vulnerability which all
An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. It has an unquoted service path that can be abused loca
A vulnerability was found in NextBX QWAlerter 4.50. It has been rated as critical. Affected by this issue is some unknow
An unquoted service path vulnerability in HCL AppScan Presence, deployed as a Windows service in HCL AppScan on Cloud (A
WAB-MAT Ver.5.0.0.8 and earlier starts another program with an unquoted file path. Since a registered Windows service pa
A vulnerability was found in AO-OPC server versions mentioned above. As the directory information for the service entry
A vulnerability was found in phjounin TFTPD64-SE 4.64 and classified as critical. This issue affects some unknown proces
Uncontrolled search path for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user
Uncontrolled search path in some Intel(R) NUC Chaco Canyon BIOS update software before version iFlashV Windows 5.13.00.2
Frequently Asked Questions
What is CWE-428?
CWE-428 (CWE-428) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-428?
There are 510 CVE records associated with CWE-428 in our database. Of these, 7 are critical severity, 337 are high severity, and 89 are medium severity.
How can I protect against CWE-428 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-428 using AI-powered security agents.
Detect CWE-428 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-428 vulnerabilities across your infrastructure.
Get Started