Fallos del tipo CWE-428

352 resultados

Caminho de busca sem aspas ou elemento não delimitado

Ocorre quando um aplicativo executa um programa ou carrega uma biblioteca usando um caminho sem aspas ou delimitação adequada, permitindo que espaços ou caracteres especiais no caminho sejam interpretados como separadores. Um atacante pode explorar isso colocando um executável malicioso em um diretório com nome parcial que coincida com a busca (ex: 'C:\Program Files\' interpretado como 'C:\Program\'), fazendo o sistema executar código não autorizado.

Ejemplo

Um serviço Windows tenta executar 'C:\Program Files\MeuApp\service.exe' mas o caminho não está entre aspas. O sistema busca primeiro por 'C:\Program.exe', depois 'C:\Program Files\MeuApp\service.exe'. Um atacante cria 'C:\Program.exe' malicioso e consegue executá-lo com privilégios do serviço.

Cómo mitigar

Sempre delimite caminhos com aspas duplas ao executar programas ou carregar bibliotecas dinâmicas. Use APIs que validem caminhos explicitamente, evite concatenação de strings para construir paths, e mantenha diretórios sensíveis com permissões restritivas para impedir criação de arquivos não autorizados.

CVE-2024-43457HIGHWindows Setup and Deployment Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2024-24722CRITICALAn unquoted service path vulnerability in the 12d Synergy Server and File Replication Server components may allow an attacker to gain elevatEPSS 0.6%CVE-2016-20057HIGHNETGATE Registry Cleaner build 16.0.205 Unquoted Service Path Privilege EscalationEPSS 0.6%CVE-2018-5470Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an unquoted search path or element vulnerability that has been identified,EPSS 0.6%CVE-2019-7487Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not put the path in quotesEPSS 0.5%CVE-2025-66575HIGHVeeVPN 1.6.1 - Unquoted Service Path Remote Code ExecutionEPSS 0.4%CVE-2018-14789In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 3.1 or prior and Xcelera Version 4.1 or prior), an unquoted search patEPSS 0.4%CVE-2014-0759MEDIUMSchneider Electric Floating License Manager Unquoted Search Path or ElementEPSS 0.4%CVE-2020-7580A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All versions < V14 SP1 EPSS 0.4%CVE-2022-46662MEDIUMRoxio Creator LJB starts another program with an unquoted file path. Since a registered Windows service path contains spaces and are unquoteEPSS 0.4%CVE-2025-14018HIGHUnquoted Service Path in NetBT Consultancy's e-FaturaEPSS 0.4%CVE-2025-34499MEDIUMAnyDesk 9.0.1 Unquoted Service Path Privilege Escalation VulnerabilityEPSS 0.4%CVE-2020-7331HIGHUnquoted service executable path in McAfee Endpoint Security (ENS)EPSS 0.4%CVE-2020-8326HIGHAn unquoted service path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authentiEPSS 0.4%CVE-2013-1609HIGHMultiple unquoted Windows search path vulnerabilities in the (1) File Collector and (2) File PlaceHolder services in Symantec Enterprise VauEPSS 0.4%CVE-2017-14019An Unquoted Search Path or Element issue was discovered in Progea Movicon Version 11.5.1181 and prior. An unquoted search path or element vuEPSS 0.4%CVE-2019-18245Reliable Controls LicenseManager versions 3.4 and prior may allow an authenticated user to insert malicious code into the system root path, EPSS 0.4%CVE-2021-21292MEDIUMUnquoted Windows binary path in TraccarEPSS 0.4%CVE-2020-7316MEDIUMFile and Removable Media Protection update fixes one vulnerabilityEPSS 0.4%CVE-2020-7581A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2EPSS 0.4%