Fallos del tipo CWE-428

352 resultados

Caminho de busca sem aspas ou elemento não delimitado

Ocorre quando um aplicativo executa um programa ou carrega uma biblioteca usando um caminho sem aspas ou delimitação adequada, permitindo que espaços ou caracteres especiais no caminho sejam interpretados como separadores. Um atacante pode explorar isso colocando um executável malicioso em um diretório com nome parcial que coincida com a busca (ex: 'C:\Program Files\' interpretado como 'C:\Program\'), fazendo o sistema executar código não autorizado.

Ejemplo

Um serviço Windows tenta executar 'C:\Program Files\MeuApp\service.exe' mas o caminho não está entre aspas. O sistema busca primeiro por 'C:\Program.exe', depois 'C:\Program Files\MeuApp\service.exe'. Um atacante cria 'C:\Program.exe' malicioso e consegue executá-lo com privilégios do serviço.

Cómo mitigar

Sempre delimite caminhos com aspas duplas ao executar programas ou carregar bibliotecas dinâmicas. Use APIs que validem caminhos explicitamente, evite concatenação de strings para construir paths, e mantenha diretórios sensíveis com permissões restritivas para impedir criação de arquivos não autorizados.

CVE-2020-8337An unquoted search path vulnerability was reported in versions prior to 1.0.83.0 of the Synaptics Smart Audio UWP app associated with the DCEPSS 0.4%CVE-2020-1988MEDIUMGlobal Protect Agent: Local privilege escalation due to an unquoted search path vulnerabilityEPSS 0.4%CVE-2017-14030An issue was discovered in Moxa MXview v2.8 and prior. The unquoted service path escalation vulnerability could allow an authorized user witEPSS 0.4%CVE-2020-8327HIGHA privilege escalation vulnerability was reported in LenovoBatteryGaugePackage for Lenovo System Interface Foundation bundled in Lenovo VantEPSS 0.4%CVE-2022-50935HIGHFLAME II MODEM USB - Unquoted Service PathEPSS 0.4%CVE-2024-58288HIGHGenexus Protection Server 9.7.2.10 Unquoted Service Path Privilege EscalationEPSS 0.3%CVE-2023-2417MEDIUMks-soft Advanced Host Monitor rma_active.exe unquoted search pathEPSS 0.3%CVE-2024-9325HIGHIntelbras InControl incontrol-service-watchdog.exe unquoted search pathEPSS 0.3%CVE-2019-25271HIGHNETGATE Data Backup 3.0.620 - 'NGDatBckpSrv' Unquoted Service PathEPSS 0.3%CVE-2019-25269HIGHAmiti Antivirus 25.0.640 - Unquoted Service Path VulnerabilityEPSS 0.3%CVE-2020-10051A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). Multiple services of the affected applicationEPSS 0.3%CVE-2025-39246MEDIUMThere is an Unquoted Service Path Vulnerability in some HikCentral FocSign versions. This could allow an authenticated user to potentially eEPSS 0.3%CVE-2021-23879MEDIUMUnquoted service path vulnerability in McAfee Endpoint Product Removal (EPR) Tool prior to 21.2 allows local administrators to execute arbitrary code, with higher-level privileges, via execution from a compromised folder. The tool did not enforce and ...EPSS 0.3%CVE-2020-7275MEDIUMUnquoted service paths for some McAfee ENS filesEPSS 0.3%CVE-2024-8975HIGHGrafana Alloy on Windows Unquoted service pathEPSS 0.3%CVE-2022-44264HIGHDentsply Sirona Sidexis <= 4.3 is vulnerable to Unquoted Service Path.EPSS 0.3%CVE-2020-7382MEDIUMUnquoted Path in Rapid7 Nexpose InstallerEPSS 0.3%CVE-2025-4540HIGHMTSoftware C-Lodop CLodopPrintService unquoted search pathEPSS 0.3%CVE-2023-7043LOWUnquoted path privilege vulnerability in ESET products for WindowsEPSS 0.3%CVE-2020-35152MEDIUMPrivilege escalation through unquoted service binary path on Cloudflare WARP for WindowsEPSS 0.3%