Fallos del tipo CWE-428

352 resultados

Caminho de busca sem aspas ou elemento não delimitado

Ocorre quando um aplicativo executa um programa ou carrega uma biblioteca usando um caminho sem aspas ou delimitação adequada, permitindo que espaços ou caracteres especiais no caminho sejam interpretados como separadores. Um atacante pode explorar isso colocando um executável malicioso em um diretório com nome parcial que coincida com a busca (ex: 'C:\Program Files\' interpretado como 'C:\Program\'), fazendo o sistema executar código não autorizado.

Ejemplo

Um serviço Windows tenta executar 'C:\Program Files\MeuApp\service.exe' mas o caminho não está entre aspas. O sistema busca primeiro por 'C:\Program.exe', depois 'C:\Program Files\MeuApp\service.exe'. Um atacante cria 'C:\Program.exe' malicioso e consegue executá-lo com privilégios do serviço.

Cómo mitigar

Sempre delimite caminhos com aspas duplas ao executar programas ou carregar bibliotecas dinâmicas. Use APIs que validem caminhos explicitamente, evite concatenação de strings para construir paths, e mantenha diretórios sensíveis com permissões restritivas para impedir criação de arquivos não autorizados.

CVE-2025-58400HIGHRATOC RAID Monitoring Manager for Windows provided by RATOC Systems, Inc. registers a Windows service with an unquoted file path. A user witEPSS 0.2%CVE-2023-6631HIGHSubnet Solutions Inc. PowerSYSTEM Center Unquoted Search Path or ElementEPSS 0.2%CVE-2020-37250HIGHTFTP Broadband 4.3.0.1465 Unquoted Service Path Privilege EscalationEPSS 0.2%CVE-2020-37251HIGHRealTimes Desktop Service 18.1.4 Unquoted Service Path Privilege EscalationEPSS 0.2%CVE-2016-20095HIGHMatrix42 Remote Control Host 3.20.0031 Unquoted Path Privilege EscalationEPSS 0.2%CVE-2020-37252HIGHRealtek Audio Service 1.0.0.55 Unquoted Service Path Privilege EscalationEPSS 0.2%CVE-2022-50933HIGHCain & Abel 4.9.56 - Unquoted Service PathEPSS 0.2%CVE-2020-36953HIGHMiniTool ShadowMaker 3.2 - 'MTAgentService' Unquoted Service PathEPSS 0.2%CVE-2020-36979HIGHAtheros Coex Service Application 8.0.0.255 -'ZAtheros Bt&Wlan Coex Agent' Unquoted Service PathEPSS 0.2%CVE-2021-47739HIGHEpic Games Easy Anti-Cheat 4.0 Local Privilege Escalation via Unquoted Service PathEPSS 0.2%CVE-2024-4461HIGHUnquoted path or search item vulnerability in SugarSyncEPSS 0.2%CVE-2022-50918HIGHVIVE Runtime Service - 'ViveAgentService' Unquoted Service PathEPSS 0.2%CVE-2022-36384MEDIUMUnquoted search path in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may alEPSS 0.2%CVE-2016-20086HIGHVembu StoreGrid 4.0 Unquoted Service Path Privilege EscalationEPSS 0.2%CVE-2025-57699HIGHWestern Digital Kitfox for Windows provided by Western Digital Corporation registers a Windows service with an unquoted file path. A user wEPSS 0.2%CVE-2016-20085HIGHRealtek High Definition Audio Driver 6.0.1.6730 Privilege EscalationEPSS 0.2%CVE-2025-12286HIGHVeePN AVService avservice.exe unquoted search pathEPSS 0.2%CVE-2022-50938HIGHCONTPAQi® AdminPAQ 14.0.0 - Unquoted Service PathEPSS 0.2%CVE-2023-2685HIGHUnquoted Service Path in ABB AO-OPCEPSS 0.2%CVE-2022-50929HIGHConnectify Hotspot 2018 'ConnectifyService' - Unquoted Service PathEPSS 0.2%