Xftp 7.0.0088p and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a c
Xmanager v7.0.0096 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via
Xlpd v7.0.0094 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a c
Xshell v7.0.0099 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a
Cloudflare Warp for Windows from version 2022.2.95.0 contained an unquoted service path which enables arbitrary code exe
Wordline HIDCCEMonitorSVC before v5.2.4.3 contains an unquoted service path which allows attackers to escalate privilege
A vulnerability has been found in FileZilla Client 3.17.0.0 and classified as problematic. This vulnerability affects un
Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker
Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted p
Aviatrix VPN Client before 2.14.14 on Windows has an unquoted search path that enables local privilege escalation to the
In Windscribe v1.83 Build 20, 'WindscribeService' has an Unquoted Service Path that facilitates privilege escalation.
The Lexmark Printer Software G2, G3 and G4 Installation Packages have a local escalation of privilege vulnerability due
The Zscaler Client Connector prior to 2.1.2.150 did not quote the search path for services, which allows a local adversa
In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquot
There is an Unquoted Service Path in NI Service Locator (nisvcloc.exe) in versions prior to 18.0 on Windows. This may al
Unquoted search path in the installer for the Intel(R) NUC M15 Laptop Kit Keyboard LED Service driver pack before versio
An unquoted service path in SAPSetup, version - 9.0, could lead to privilege escalation during the installation process
Unquoted service path in the Intel Unite(R) Client for Windows before version 4.2.25031 may allow an authenticated user
Unquoted service path vulnerability in McAfee Endpoint Product Removal (EPR) Tool prior to 21.2 allows local administrat
Unisys Stealth 5.1 before 5.1.025.0 and 6.0 before 6.0.055.0 has an unquoted Windows search path for a scheduled task. A
As a result of an unquoted service path vulnerability present in the Kiwi Syslog Server Installation Wizard, a local att
An issue was discovered in the CheckUser extension for MediaWiki through 1.35.2. MediaWiki usernames with trailing white
Traccar is an open source GPS tracking system. In Traccar before version 4.12 there is an unquoted Windows binary path v
SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to
Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary
Cloudflare WARP for Windows allows privilege escalation due to an unquoted service path. A malicious user or process run
A local administrator could prevent the HMPA service from starting despite tamper protection using an unquoted service p
An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior all
An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated p
The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\
The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\
An unquoted search path vulnerability exists in HDD Password tool (for Windows) version 1.20.6620 and earlier which is s
On Windows the Veyon Service before version 4.4.2 contains an unquoted service path vulnerability, allowing locally auth
In Teradici PCoIP Agent before 19.08.1 and PCoIP Client before 19.08.3, an unquoted service path can cause execution of
A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consume
A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version
Unquoted service path in Intel(R) Optane(TM) DC Persistent Memory Module Management Software before version 1.0.0.3461 m
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). Multiple services of the
Unquoted service executable path in McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows local use
A privilege escalation vulnerability was reported in LenovoBatteryGaugePackage for Lenovo System Interface Foundation bu
An unquoted service path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that cou
A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installe
Rapid7 Nexpose installer version prior to 6.6.40 contains an Unquoted Search Path which may allow an attacker on the loc
An unquoted search path vulnerability was reported in versions prior to 1.0.83.0 of the Synaptics Smart Audio UWP app as
A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All
A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation
Unquoted service path vulnerability in McAfee File and Removable Media Protection (FRP) prior to 5.3.0 allows local user
whoopsie-daisy before 0.1.26: Root user can remove arbitrary files
Accessing, modifying or executing executable files vulnerability in the uninstaller in McAfee Endpoint Security (ENS) fo
Unquoted service path in Intel(R) Graphics Drivers before versions 15.33.49.5100, 15.36.38.5117, 15.40.44.5107, 15.45.30
Frequently Asked Questions
What is CWE-428?
CWE-428 (CWE-428) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-428?
There are 510 CVE records associated with CWE-428 in our database. Of these, 7 are critical severity, 337 are high severity, and 89 are medium severity.
How can I protect against CWE-428 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-428 using AI-powered security agents.
Detect CWE-428 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-428 vulnerabilities across your infrastructure.
Get Started