Fallos del tipo CWE-428

352 resultados

Caminho de busca sem aspas ou elemento não delimitado

Ocorre quando um aplicativo executa um programa ou carrega uma biblioteca usando um caminho sem aspas ou delimitação adequada, permitindo que espaços ou caracteres especiais no caminho sejam interpretados como separadores. Um atacante pode explorar isso colocando um executável malicioso em um diretório com nome parcial que coincida com a busca (ex: 'C:\Program Files\' interpretado como 'C:\Program\'), fazendo o sistema executar código não autorizado.

Ejemplo

Um serviço Windows tenta executar 'C:\Program Files\MeuApp\service.exe' mas o caminho não está entre aspas. O sistema busca primeiro por 'C:\Program.exe', depois 'C:\Program Files\MeuApp\service.exe'. Um atacante cria 'C:\Program.exe' malicioso e consegue executá-lo com privilégios do serviço.

Cómo mitigar

Sempre delimite caminhos com aspas duplas ao executar programas ou carregar bibliotecas dinâmicas. Use APIs que validem caminhos explicitamente, evite concatenação de strings para construir paths, e mantenha diretórios sensíveis com permissões restritivas para impedir criação de arquivos não autorizados.

CVE-2023-54331HIGHOutline 1.6.0 - Unquoted Service PathEPSS 0.2%CVE-2022-50923HIGHCobian Backup 0.9 - Unquoted Service PathEPSS 0.2%CVE-2024-1201HIGHPanteraSoft HDD Health search path or unquoted item vulnerabilityEPSS 0.2%CVE-2023-5012MEDIUMTopaz OFD Protection Module Warsaw core.exe unquoted search pathEPSS 0.2%CVE-2022-50915HIGHPTPublisher 2.3.4 - Unquoted Service PathEPSS 0.2%CVE-2022-50917HIGHProtonVPN 1.26.0 - Unquoted Service PathEPSS 0.2%CVE-2022-27592MEDIUMQVR Smart ClientEPSS 0.2%CVE-2026-33253HIGHSANUPS SOFTWARE provided by SANYO DENKI CO., LTD. registers Windows services with unquoted file paths. A user with the write permission on tEPSS 0.2%CVE-2023-25075MEDIUMUnquoted search path in the installer for some Intel Server Configuration Utility software before version 16.0.9 may allow an authenticated EPSS 0.2%CVE-2019-25276HIGHStudio 5000 Logix Designer 30.01.00 - 'FactoryTalk Activation Service' Unquoted Service PathEPSS 0.2%CVE-2023-2331HIGHBypassing hardening via Unquoted Service path vulnerabilityEPSS 0.2%CVE-2025-61865HIGHMultiple NAS management applications provided by I-O DATA DEVICE, INC. register Windows services with unquoted file paths. A user with the wEPSS 0.2%CVE-2022-0357MEDIUMImproper Quoting Path Issue in Bitdefender Total SecurityEPSS 0.2%CVE-2020-37100HIGHSync Breeze Enterprise 12.4.18 - Unquoted Service PathEPSS 0.2%CVE-2023-24542MEDIUMUnquoted search path or element in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user tEPSS 0.2%CVE-2022-50928HIGHBluetooth Application 5.4.277 - 'BlueSoleilCS' Unquoted Service PathEPSS 0.2%CVE-2022-50921HIGHWOW21 5.0.1.9 - 'Service WOW21_Service' Unquoted Service PathEPSS 0.2%CVE-2020-36977HIGHWondershare Driver Install Service help 10.7.1.321 - 'ElevationService' Unquote Service PathEPSS 0.2%CVE-2025-24831MEDIUMLocal privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber Protect Cloud AgentEPSS 0.2%CVE-2022-50924HIGHPrivate Internet Access 3.3 - 'pia-service' Unquoted Service PathEPSS 0.2%