Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-428

MITRE ↗

CWE-428

7
CRITICAL
337
HIGH
89
MEDIUM
3
LOW
447 CVEs · Page 7/9
6.7
CVE-2022-41693

Uncontrolled search path in the Intel(R) Quartus(R) Prime Pro edition software before version 22.3 may allow an authenti

6.7
CVE-2022-43474

Uncontrolled search path for the DSP Builder software installer before version 22.4 for Intel(R) FPGAs Pro Edition may a

6.7
CVE-2023-27386

Uncontrolled search path in some Intel(R) Pathfinder for RISC-V software may allow an authenticated user to potentially

6.7
CVE-2022-0357

Unquoted Search Path or Element vulnerability in the Vulnerability Scan component of Bitdefender Total Security, Bitdefe

6.7
CVE-2023-22841

Unquoted search path in the software installer for the System Firmware Update Utility (SysFwUpdt) for some Intel(R) Serv

6.7
CVE-2021-26735

The Zscaler Client Connector Installer and Unsintallers for Windows prior to 3.6 had an unquoted search path vulnerabili

6.7
CVE-2023-0392

The LDAP Agent Update service with versions prior to 5.18 used an unquoted path, which could allow arbitrary code execut

6.7
CVE-2023-25075

Unquoted search path in the installer for some Intel Server Configuration Utility software before version 16.0.9 may all

6.7
CVE-2023-29165

Unquoted search path or element in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authen

6.7
CVE-2023-32658

Unquoted search path in some Intel(R) NUC Kits NUC7i3DN, NUC7i5DN, NUC7i7DN HDMI firmware update tool software before ve

6.3
CVE-2023-42486

Fortect - CWE-428: Unquoted Search Path or Element, may be used by local user to elevate privileges.

5.3
CVE-2022-4429

Avira Security for Windows contains an unquoted service path which allows attackers with local administrative privileges

5.3
CVE-2023-2417

A vulnerability was found in ks-soft Advanced Host Monitor up to 12.56 and classified as problematic. Affected by this i

5.3
CVE-2023-2644

A vulnerability, which was classified as problematic, has been found in DigitalPersona FPSensor 1.0.0.1. This issue affe

5.3
CVE-2023-5012

A vulnerability, which was classified as problematic, was found in Topaz OFD 2.11.0.201. This affects an unknown part of

4.4
CVE-2023-3438

An unquoted Windows search path vulnerability existed in the install the MOVE 4.10.x and earlier Windows install servic

9.8
CVE-2022-36344

An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple pro

8.3
CVE-2020-14521

Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerabil

8.1
CVE-2021-45460

A vulnerability has been identified in SICAM PQ Analyzer (All versions < V3.18). A service is started by an unquoted reg

7.8
CVE-2021-46368

TRIGONE Remote System Monitor 3.61 is vulnerable to an unquoted path service allowing local users to launch processes wi

7.8
CVE-2022-25031

Remote Desktop Commander Suite Agent before v4.8 contains an unquoted service path which allows attackers to escalate pr

7.8
CVE-2022-27050

BitComet Service for Windows before version 1.8.6 contains an unquoted service path vulnerability which allows attackers

7.8
CVE-2022-27052

FreeFtpd version 1.0.13 and below contains an unquoted service path vulnerability which allows local users to launch pro

7.8
CVE-2021-43454

An Unquoted Service Path vulnerability exists in AnyTXT Searcher 1.2.394 via a specially crafted file in the ATService p

7.8
CVE-2021-43455

An Unquoted Service Path vulnerability exists in FreeLAN 2.2 via a specially crafted file in the FreeLAN Service path.

7.8
CVE-2021-43456

An Unquoted Service Path vulnerablility exists in Rumble Mail Server 0.51.3135 via via a specially crafted file in the R

7.8
CVE-2021-43457

An Unquoted Service Path vulnerability exists in bVPN 2.5.1 via a specially crafted file in the waselvpnserv service pat

7.8
CVE-2021-43458

An Unquoted Service Path vulnerability exits in Vembu BDR 4.2.0.1 via a specially crafted file in the (1) hsflowd, (2) V

7.8
CVE-2021-43460

An Unquoted Service Path vulnerability exists in System Explorer 7.0.0 via via a specially crafted file in the SystemExp

7.8
CVE-2021-43463

An Unquoted Service Path vulnerability exists in Ext2Fsd v0.68 via a specially crafted file in the Ext2Srv Service execu

7.8
CVE-2022-23909

There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might

7.8
CVE-2022-27088

Ivanti DSM Remote <= 6.3.1.1862 is vulnerable to an unquoted service path allowing local users to launch processes with

7.8
CVE-2022-27089

In Fujitsu PlugFree Network <= 7.3.0.3, an Unquoted service path in PFNService.exe software allows a local attacker to p

7.8
CVE-2022-26634

HMA VPN v5.3.5913.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.

7.8
CVE-2022-27095

BattlEye v0.9 contains an unquoted service path which allows attackers to escalate privileges to the system level.

7.8
CVE-2022-29320

MiniTool Partition Wizard v12.0 contains an unquoted service path which allows attackers to escalate privileges to the s

7.8
CVE-2022-31590

SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to

7.8
CVE-2022-31591

SAP BusinessObjects BW Publisher Service - versions 420, 430, uses a search path that contains an unquoted element. A lo

7.8
CVE-2022-35899

There is an unquoted service path in ASUSTeK Aura Ready Game SDK service (GameSDK.exe) 1.0.0.4. This might allow a local

7.8
CVE-2022-35292

In SAP Business One application when a service is created, the executable path contains spaces and isn’t enclosed within

7.8
CVE-2022-39959

Panini Everest Engine 2.0.4 allows unprivileged users to create a file named Everest.exe in the %PROGRAMDATA%\Panini fol

7.8
CVE-2022-33920

Dell GeoDrive, versions prior to 2.2, contains an Unquoted File Path vulnerability. A low privilege attacker could poten

7.8
CVE-2022-37197

IOBit IOTransfer V4 is vulnerable to Unquoted Service Path.

7.8
CVE-2019-19705

Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1

7.3
CVE-2022-0883

SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.

7.2
CVE-2022-27905

In ControlUp Real-Time Agent before 8.6, an unquoted path can result in privilege escalation. An attacker would require

6.7
CVE-2021-29218

A local unquoted search path security vulnerability has been identified in HPE Agentless Management Service for Windows

6.7
CVE-2022-27094

Sony PlayMemories Home v6.0 contains an unquoted service path which allows attackers to escalate privileges to the syste

6.7
CVE-2022-36384

Unquoted search path in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before

6.7
CVE-2022-46662

Roxio Creator LJB starts another program with an unquoted file path. Since a registered Windows service path contains sp

Frequently Asked Questions

What is CWE-428?

CWE-428 (CWE-428) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-428?

There are 510 CVE records associated with CWE-428 in our database. Of these, 7 are critical severity, 337 are high severity, and 89 are medium severity.

How can I protect against CWE-428 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-428 using AI-powered security agents.

Detect CWE-428 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-428 vulnerabilities across your infrastructure.

Get Started