Unquoted service executable path in DXL Broker in McAfee Data eXchange Layer (DXL) Framework 6.0.0 and earlier allows lo
An unquoted search path vulnerability in the Windows release of Global Protect Agent allows an authenticated local user
Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without us
An unquoted search path vulnerability in some pre-installed applications on Panasonic PC run on Windows 7 (32bit), Windo
In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing
WINMAGIC SecureDoc Disk Encryption software before 8.3 has an Unquoted Service Path vulnerability, which could allow an
A local privilege escalation vulnerability exists in Trend Micro Security 2019 (v15.0) in which, if exploited, would all
An unquoted service path vulnerability is reported to affect the service QVssService in QNAP NetBak Replicator. This vul
Reliable Controls LicenseManager versions 3.4 and prior may allow an authenticated user to insert malicious code into th
Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not pu
An unquoted search path vulnerability in Multiple Yokogawa products for Windows (Exaopc (R1.01.00 ? R3.77.00), Exaplog (
The BIND installer on Windows uses an unquoted service path which can enable a local user to achieve privilege escalatio
Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows.
An unquoted search path vulnerability was identified in Lenovo Dynamic Power Reduction Utility prior to version 2.2.2.0
Unquoted service path in the installer for the Intel(R) SCS Discovery Utility version 12.0.0.129 and earlier may allow a
ExacqVision Server’s services 'exacqVisionServer', 'dvrdhcpserver' and 'mdnsresponder' have an unquoted service path. If
Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability. This enables loc
An issue was discovered in Moxa MXview v2.8 and prior. The unquoted service path escalation vulnerability could allow an
FreeSSHd 1.3.1 version is vulnerable to an Unquoted Path Service allowing local users to launch processes with elevated
Unquoted Windows search path vulnerability in NSClient++ before 0.4.1.73 allows non-privileged local users to execute ar
Unquoted Windows search path vulnerability in the srvInventoryWebServer service in 10-Strike Network Monitor 5.4 allows
Unquoted Windows search path vulnerability in the panda_url_filtering service in Panda Global Protection 17.0.1 allows l
Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an unquoted search path or element vulnerability that
Without quotation marks, any whitespace in the file path for Rockwell Automation FactoryTalk Activation version 4.00.02
Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Unquoted Search Path vulnera
An unquoted search path or element in RSLinx Classic Versions 3.90.01 and prior and FactoryTalk Linx Gateway Versions 3.
The OPC Foundation Local Discovery Server (LDS) before 1.03.367 is installed as a Windows Service without adding double
Unquoted service paths in Intel Processor Diagnostic Tool (IPDT) before version 4.1.0.27 allows a local attacker to pote
Unquoted service paths in Intel Quartus Prime in versions 15.1 - 18.0 allow a local attacker to potentially execute arbi
Unquoted service paths in Intel Quartus II in versions 11.0 - 15.0 allow a local attacker to potentially execute arbitra
Unquoted service paths in Intel Quartus II Programmer and Tools in versions 11.0 - 15.0 allow a local attacker to potent
Unquoted service paths in Intel Quartus Prime Programmer and Tools in versions 15.1 - 18.0 allow a local attacker to pot
Dell WMS versions 1.1 and prior are impacted by multiple unquoted service path vulnerabilities. Affected software instal
In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 3.1 or prior and Xcelera Version 4.1 or prior), an
Unquoted windows search path (directory/path traversal) vulnerability in Crystal Reports Server, OEM Edition (CRSE), 4.0
Unquoted service path vulnerability in Lenovo Edge and Lenovo Slim USB Keyboard Driver versions earlier than 1.21 allows
Adobe Photoshop versions CC 2017 (18.0.1) and earlier, CC 2015.5.1 (17.0.1) and earlier have an unquoted search path vul
Multiple unquoted service path vulnerabilities in Sierra Wireless Windows Mobile Broadband Driver Package (MBDP) with bu
An unquoted service path vulnerability was identified in the driver for the ThinkPad Compact USB Keyboard with TrackPoin
An unquoted service path vulnerability was identified in the driver for the ElanTech Touchpad, various versions, used on
An Uncontrolled Search Path or Element issue was discovered in i-SENS SmartLog Diabetes Management Software, Version 2.4
An Unquoted Search Path issue was discovered in mySCADA myPRO Versions 7.0.26 and prior. Application services utilize un
Nero 7.10.1.0 has an unquoted BINARY_PATH_NAME for NBService, exploitable via a Trojan horse Nero.exe file in the %PROGR
Net Monitor for Employees Pro through 5.3.4 has an unquoted service path, which allows a Security Feature Bypass of its
An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan
Unquoted Windows search path vulnerability in the guest service in Unisys s-Par before 4.4.20 allows local users to gain
An Unquoted Search Path or Element issue was discovered in Progea Movicon Version 11.5.1181 and prior. An unquoted searc
Frequently Asked Questions
What is CWE-428?
CWE-428 (CWE-428) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-428?
There are 510 CVE records associated with CWE-428 in our database. Of these, 7 are critical severity, 337 are high severity, and 89 are medium severity.
How can I protect against CWE-428 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-428 using AI-powered security agents.
Detect CWE-428 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-428 vulnerabilities across your infrastructure.
Get Started