Uncontrolled search path in the Intel(R) Quartus(R) Prime Pro edition software before version 22.3 may allow an authenti
Uncontrolled search path for the DSP Builder software installer before version 22.4 for Intel(R) FPGAs Pro Edition may a
Uncontrolled search path in some Intel(R) Pathfinder for RISC-V software may allow an authenticated user to potentially
Unquoted Search Path or Element vulnerability in the Vulnerability Scan component of Bitdefender Total Security, Bitdefe
Unquoted search path in the software installer for the System Firmware Update Utility (SysFwUpdt) for some Intel(R) Serv
The Zscaler Client Connector Installer and Unsintallers for Windows prior to 3.6 had an unquoted search path vulnerabili
The LDAP Agent Update service with versions prior to 5.18 used an unquoted path, which could allow arbitrary code execut
Unquoted search path in the installer for some Intel Server Configuration Utility software before version 16.0.9 may all
Unquoted search path or element in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authen
Unquoted search path in some Intel(R) NUC Kits NUC7i3DN, NUC7i5DN, NUC7i7DN HDMI firmware update tool software before ve
Fortect - CWE-428: Unquoted Search Path or Element, may be used by local user to elevate privileges.
Avira Security for Windows contains an unquoted service path which allows attackers with local administrative privileges
A vulnerability was found in ks-soft Advanced Host Monitor up to 12.56 and classified as problematic. Affected by this i
A vulnerability, which was classified as problematic, has been found in DigitalPersona FPSensor 1.0.0.1. This issue affe
A vulnerability, which was classified as problematic, was found in Topaz OFD 2.11.0.201. This affects an unknown part of
An unquoted Windows search path vulnerability existed in the install the MOVE 4.10.x and earlier Windows install servic
An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple pro
Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerabil
A vulnerability has been identified in SICAM PQ Analyzer (All versions < V3.18). A service is started by an unquoted reg
TRIGONE Remote System Monitor 3.61 is vulnerable to an unquoted path service allowing local users to launch processes wi
Remote Desktop Commander Suite Agent before v4.8 contains an unquoted service path which allows attackers to escalate pr
BitComet Service for Windows before version 1.8.6 contains an unquoted service path vulnerability which allows attackers
FreeFtpd version 1.0.13 and below contains an unquoted service path vulnerability which allows local users to launch pro
An Unquoted Service Path vulnerability exists in AnyTXT Searcher 1.2.394 via a specially crafted file in the ATService p
An Unquoted Service Path vulnerability exists in FreeLAN 2.2 via a specially crafted file in the FreeLAN Service path.
An Unquoted Service Path vulnerablility exists in Rumble Mail Server 0.51.3135 via via a specially crafted file in the R
An Unquoted Service Path vulnerability exists in bVPN 2.5.1 via a specially crafted file in the waselvpnserv service pat
An Unquoted Service Path vulnerability exits in Vembu BDR 4.2.0.1 via a specially crafted file in the (1) hsflowd, (2) V
An Unquoted Service Path vulnerability exists in System Explorer 7.0.0 via via a specially crafted file in the SystemExp
An Unquoted Service Path vulnerability exists in Ext2Fsd v0.68 via a specially crafted file in the Ext2Srv Service execu
There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might
Ivanti DSM Remote <= 6.3.1.1862 is vulnerable to an unquoted service path allowing local users to launch processes with
In Fujitsu PlugFree Network <= 7.3.0.3, an Unquoted service path in PFNService.exe software allows a local attacker to p
HMA VPN v5.3.5913.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.
BattlEye v0.9 contains an unquoted service path which allows attackers to escalate privileges to the system level.
MiniTool Partition Wizard v12.0 contains an unquoted service path which allows attackers to escalate privileges to the s
SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to
SAP BusinessObjects BW Publisher Service - versions 420, 430, uses a search path that contains an unquoted element. A lo
There is an unquoted service path in ASUSTeK Aura Ready Game SDK service (GameSDK.exe) 1.0.0.4. This might allow a local
In SAP Business One application when a service is created, the executable path contains spaces and isn’t enclosed within
Panini Everest Engine 2.0.4 allows unprivileged users to create a file named Everest.exe in the %PROGRAMDATA%\Panini fol
Dell GeoDrive, versions prior to 2.2, contains an Unquoted File Path vulnerability. A low privilege attacker could poten
IOBit IOTransfer V4 is vulnerable to Unquoted Service Path.
Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1
SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.
In ControlUp Real-Time Agent before 8.6, an unquoted path can result in privilege escalation. An attacker would require
A local unquoted search path security vulnerability has been identified in HPE Agentless Management Service for Windows
Sony PlayMemories Home v6.0 contains an unquoted service path which allows attackers to escalate privileges to the syste
Unquoted search path in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before
Roxio Creator LJB starts another program with an unquoted file path. Since a registered Windows service path contains sp
Frequently Asked Questions
What is CWE-428?
CWE-428 (CWE-428) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-428?
There are 510 CVE records associated with CWE-428 in our database. Of these, 7 are critical severity, 337 are high severity, and 89 are medium severity.
How can I protect against CWE-428 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-428 using AI-powered security agents.
Detect CWE-428 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-428 vulnerabilities across your infrastructure.
Get Started