Fallos del tipo CWE-428

352 resultados

Caminho de busca sem aspas ou elemento não delimitado

Ocorre quando um aplicativo executa um programa ou carrega uma biblioteca usando um caminho sem aspas ou delimitação adequada, permitindo que espaços ou caracteres especiais no caminho sejam interpretados como separadores. Um atacante pode explorar isso colocando um executável malicioso em um diretório com nome parcial que coincida com a busca (ex: 'C:\Program Files\' interpretado como 'C:\Program\'), fazendo o sistema executar código não autorizado.

Ejemplo

Um serviço Windows tenta executar 'C:\Program Files\MeuApp\service.exe' mas o caminho não está entre aspas. O sistema busca primeiro por 'C:\Program.exe', depois 'C:\Program Files\MeuApp\service.exe'. Um atacante cria 'C:\Program.exe' malicioso e consegue executá-lo com privilégios do serviço.

Cómo mitigar

Sempre delimite caminhos com aspas duplas ao executar programas ou carregar bibliotecas dinâmicas. Use APIs que validem caminhos explicitamente, evite concatenação de strings para construir paths, e mantenha diretórios sensíveis com permissões restritivas para impedir criação de arquivos não autorizados.

CVE-2022-50924HIGHPrivate Internet Access 3.3 - 'pia-service' Unquoted Service PathEPSS 0.2%CVE-2024-22437HIGHHPE MSA SAN Storage VSS Provider and CAPI Proxy Software, Elevation of PrivilegeEPSS 0.2%CVE-2016-20094HIGHAnyDesk 2.5.0 Unquoted Service Path Elevation of PrivilegeEPSS 0.2%CVE-2026-26033HIGHUPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Unquoted Search Path or Element (CWE-428) vulnerability, which EPSS 0.2%CVE-2023-24575HIGH Dell Multifunction Printer E525w Driver and Software Suite, versions prior to 1.047.2022, A05, contain a local privilege escalation vulneraEPSS 0.2%CVE-2024-5402MEDIUMMint Workbench I Unquoted Service Path EnumerationEPSS 0.2%CVE-2022-50914HIGHEaseUS Data Recovery - 'ensserver.exe' Unquoted Service PathEPSS 0.2%CVE-2025-10199HIGHA local privilege escalation vulnerability exists in LizardBytes' Sunshine for WindowsEPSS 0.2%CVE-2016-20059HIGHIObit Malware Fighter 4.3.1 Unquoted Service Path Privilege EscalationEPSS 0.2%CVE-2023-53984HIGHHotKey Clipboard 2.1.0.6 - Privilege Escalation Unquoted Service PathEPSS 0.2%CVE-2016-20055HIGHIObit Advanced SystemCare 10.0.2 Unquoted Service Path Privilege EscalationEPSS 0.2%CVE-2016-20087HIGHFortitude HTTP 1.0.4.0 Unquoted Service Path Elevation of PrivilegeEPSS 0.2%CVE-2023-54353HIGHChromacam 4.0.3.0 Unquoted Service Path Privilege EscalationEPSS 0.2%CVE-2016-20092HIGHNetDrive 2.6.12 Unquoted Service Path Elevation of PrivilegeEPSS 0.2%CVE-2019-25747HIGHNetwork Inventory Advisor 5.0.26.0 Unquoted Service Path Privilege EscalationEPSS 0.2%CVE-2016-20090HIGHComodo Dragon Browser 52.15.25.663 Privilege Escalation via Unquoted Service PathEPSS 0.2%CVE-2016-20088HIGHComodo Chromodo Browser 52.15.25.664 Unquoted Service Path Privilege EscalationEPSS 0.2%CVE-2020-37254HIGHWondershare PDFelement 5.2.9 Privilege Escalation via Unquoted Service PathEPSS 0.2%CVE-2016-20089HIGHIperius Remote 1.7.0 Unquoted Service Path Elevation of PrivilegeEPSS 0.2%CVE-2016-20093HIGHWise Care 365 4.27 and Wise Disk Cleaner 9.29 Unquoted Service Path Privilege EscalationEPSS 0.2%