← Back
CWE-428

450 CVEs • Abstraction: Base

Unquoted Search Path or Element

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

JSON object

Loading...

CVEs (450)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sap
1Business One
Jun 17, 2026
Sep 13, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In SAP Business One application when a service is created, the executable path contains spaces and isn’t enclosed within quotes, leading to a vulnerability known as Unquoted Service Path which allows a user to gain SYSTE...Show more
In SAP Business One application when a service is created, the executable path contains spaces and isn’t enclosed within quotes, leading to a vulnerability known as Unquoted Service Path which allows a user to gain SYSTEM privileges. If the service is exploited by adversaries, it can be used to gain privileged permissions on a system or network leading to high impact on Confidentiality, Integrity, and Availability.Show less
1Okta
1Active Directory Agent
Jun 17, 2026
Sep 6, 2022
N/A· v4
3.9 LOW· v3
N/A· v2
Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted path. Note: To remediate this vulnerability, you must uninstall Okta Active Directory Agent and reins...Show more
Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted path. Note: To remediate this vulnerability, you must uninstall Okta Active Directory Agent and reinstall Okta Active Directory Agent 3.12.0 or greater per the documentation.Show less
1Justsystems
60Atok Medical 2
Atok Medical 3Atok Pro 3+57 more
Jun 17, 2026
Aug 16, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts...Show more
An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed with the privilege of the Windows service if it is placed in a certain path. Affected products are bundled with the following product series: Office and Office Integrated Software, ATOK, Hanako, JUST PDF, Shuriken, Homepage Builder, JUST School, JUST Smile Class, JUST Smile, JUST Frontier, JUST Jump, and Tri-De DetaProtect.Show less
1Asus
1Aura Ready Game Software Development Kit
Jun 17, 2026
Jul 21, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
There is an unquoted service path in ASUSTeK Aura Ready Game SDK service (GameSDK.exe) 1.0.0.4. This might allow a local user to escalate privileges by creating a %PROGRAMFILES(X86)%\ASUS\GameSDK.exe file.
1Filezilla Project
1Filezilla Client
Nov 21, 2024
Jul 18, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A vulnerability has been found in FileZilla Client 3.17.0.0 and classified as problematic. This vulnerability affects unknown code of the file C:\Program Files\FileZilla FTP Client\uninstall.exe of the component Installe...Show more
A vulnerability has been found in FileZilla Client 3.17.0.0 and classified as problematic. This vulnerability affects unknown code of the file C:\Program Files\FileZilla FTP Client\uninstall.exe of the component Installer. The manipulation leads to unquoted search path. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.Show less
1Sap
1Businessobjects Bw Publisher Service
Jun 17, 2026
Jul 12, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
SAP BusinessObjects BW Publisher Service - versions 420, 430, uses a search path that contains an unquoted element. A local attacker can gain elevated privileges by inserting an executable file in the path of the affecte...Show more
SAP BusinessObjects BW Publisher Service - versions 420, 430, uses a search path that contains an unquoted element. A local attacker can gain elevated privileges by inserting an executable file in the path of the affected serviceShow less
1Cloudflare
1Warp
Jun 17, 2026
Jun 23, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Cloudflare Warp for Windows from version 2022.2.95.0 contained an unquoted service path which enables arbitrary code execution leading to privilege escalation. The fix was released in version 2022.3.186.0.
1Sap
1Powerdesigner Proxy
Jun 17, 2026
Jun 14, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to work around system’s root disk access restrictions to Write/Create a program file on system disk ro...Show more
SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to work around system’s root disk access restrictions to Write/Create a program file on system disk root path, which could then be executed with elevated privileges of the application during application start up or reboot, potentially compromising Confidentiality, Integrity and Availability of the system.Show less
1Minitool
1Partition Wizard
Jun 17, 2026
May 20, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
MiniTool Partition Wizard v12.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.
1Battleye
1Battleye
Jun 17, 2026
May 20, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
BattlEye v0.9 contains an unquoted service path which allows attackers to escalate privileges to the system level.
1Sony
1Playmemories Home
Jun 17, 2026
May 20, 2022
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
Sony PlayMemories Home v6.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.
1Hma
1Hidemyass
Jun 17, 2026
May 20, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
HMA VPN v5.3.5913.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.
1Snowsoftware
1Snow License Manager
Jun 17, 2026
May 18, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.20.1 should be patched.
1Controlup
1Controlup
Jun 17, 2026
Apr 27, 2022
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
In ControlUp Real-Time Agent before 8.6, an unquoted path can result in privilege escalation. An attacker would require write permissions to the root level of the OS drive (C:\) to exploit this.
1Fujitsu
1Plugfree Network
Jun 17, 2026
Apr 11, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In Fujitsu PlugFree Network <= 7.3.0.3, an Unquoted service path in PFNService.exe software allows a local attacker to potentially escalate privileges to system level.
1Ivanti
1Dsm Remote
Jun 17, 2026
Apr 11, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Ivanti DSM Remote <= 6.3.1.1862 is vulnerable to an unquoted service path allowing local users to launch processes with elevated privileges.
1Gimmal
1Sherpa Connector Service
Jun 17, 2026
Apr 5, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might allow a local user to escalate privileges by creating a "C:\Program Files\Sherpa Software\Sherpa.ex...Show more
There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might allow a local user to escalate privileges by creating a "C:\Program Files\Sherpa Software\Sherpa.exe" file.Show less
1Ext2 File System Driver Project
1Ext2 File System Driver
Jun 17, 2026
Apr 4, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An Unquoted Service Path vulnerability exists in Ext2Fsd v0.68 via a specially crafted file in the Ext2Srv Service executable service path.
1Systemexplorer
1System Explorer
Jun 17, 2026
Apr 4, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An Unquoted Service Path vulnerability exists in System Explorer 7.0.0 via via a specially crafted file in the SystemExplorerHelpService service executable path.
1Vembu
1Bdr Suite
Jun 17, 2026
Apr 4, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An Unquoted Service Path vulnerability exits in Vembu BDR 4.2.0.1 via a specially crafted file in the (1) hsflowd, (2) VembuBDR360Agent, or (3) VembuOffice365Agent service paths.