Fallos del tipo CWE-428

352 resultados

Caminho de busca sem aspas ou elemento não delimitado

Ocorre quando um aplicativo executa um programa ou carrega uma biblioteca usando um caminho sem aspas ou delimitação adequada, permitindo que espaços ou caracteres especiais no caminho sejam interpretados como separadores. Um atacante pode explorar isso colocando um executável malicioso em um diretório com nome parcial que coincida com a busca (ex: 'C:\Program Files\' interpretado como 'C:\Program\'), fazendo o sistema executar código não autorizado.

Ejemplo

Um serviço Windows tenta executar 'C:\Program Files\MeuApp\service.exe' mas o caminho não está entre aspas. O sistema busca primeiro por 'C:\Program.exe', depois 'C:\Program Files\MeuApp\service.exe'. Um atacante cria 'C:\Program.exe' malicioso e consegue executá-lo com privilégios do serviço.

Cómo mitigar

Sempre delimite caminhos com aspas duplas ao executar programas ou carregar bibliotecas dinâmicas. Use APIs que validem caminhos explicitamente, evite concatenação de strings para construir paths, e mantenha diretórios sensíveis com permissões restritivas para impedir criação de arquivos não autorizados.

CVE-2020-36990HIGHInput Director 1.4.3 - 'Input Director' Unquoted Service PathEPSS 0.2%CVE-2020-36992HIGHNord VPN-6.31.13.0 - 'nordvpn-service' Unquoted Service PathEPSS 0.2%CVE-2020-36991HIGHShareMouse 5.0.43 - 'ShareMouse Service' Unquoted Service PathEPSS 0.2%CVE-2021-47825HIGHAcer Updater Service 1.2.3500.0 - 'UpdaterService.exe' Unquoted Service PathEPSS 0.2%CVE-2020-36986HIGHPrey 1.9.6 - "CronService" Unquoted Service PathEPSS 0.2%CVE-2020-36984HIGHEPSON 1.124 - 'seksmdb.exe' Unquoted Service PathEPSS 0.2%CVE-2020-36989HIGHForensiTAppxService 2.2.0.4 - 'ForensiTAppxService.exe' Unquoted Service PathEPSS 0.2%CVE-2023-54336HIGHMediconta 3.7.27 - 'servermedicontservice' Unquoted Service PathEPSS 0.2%CVE-2025-12247HIGHHasleo Backup Suite HasleoImageMountService/HasleoBackupSuiteService unquoted search pathEPSS 0.2%CVE-2019-25288HIGHWacom WTabletService 6.6.7-3 - 'WTabletServicePro' Unquoted Service PathEPSS 0.2%CVE-2019-25292HIGHAlps HID Monitor Service 8.1.0.10 - 'ApHidMonitorService' Unquote Service PathEPSS 0.2%CVE-2026-2542HIGHTotal VPN win-service.exe unquoted search pathEPSS 0.2%CVE-2020-37253HIGHWinstep 18.06.0096 Unquoted Service Path Privilege EscalationEPSS 0.2%CVE-2020-36987HIGHProgram Access Controller v1.2.0.0 - 'PACService.exe' Unquoted Service PathEPSS 0.2%CVE-2020-36985HIGHIP Watcher v3.0.0.30 - 'PACService.exe' Unquoted Service PathEPSS 0.2%CVE-2025-41359HIGHMultiple vulnerabilities in Small HTTP server by SmallsrvEPSS 0.2%CVE-2016-20056HIGHSpy Emergency build 23.0.205 Unquoted Service Path Privilege EscalationEPSS 0.2%CVE-2025-61871HIGHNAS Navigator2 Windows version by BUFFALO INC. registers a Windows service with an unquoted file path. A user with the write permission on tEPSS 0.2%CVE-2025-62225HIGHOptical Disc Archive Software provided by Sony Corporation registers a Windows service with an unquoted file path. A user with the write perEPSS 0.2%CVE-2025-8070CRITICALWindows service registered with an unquoted ImagePath vulnerability in the system registryEPSS 0.2%