CWE-428: CWE-428
Yearly Trend
Top Affected Vendors
All CWE-428 CVEs (127)
CVE-2021-27608 is an unquoted service path vulnerability in SAPSetup version 9.0 that allows local attackers to escalate privileges during installatio...
Apr 14, 2021This CVE describes an unquoted search path vulnerability in NetBT Consulting Services Inc.'s E-Fatura software. Attackers can manipulate configuration...
Dec 22, 2025This vulnerability allows a local attacker to escalate privileges by exploiting an unquoted search path in AMD Cloud Manageability Service. Attackers ...
May 13, 2025This vulnerability in AMD's AIM-T Manageability Service allows local attackers to escalate privileges by exploiting an unquoted search path. Attackers...
May 13, 2025This CVE describes an unquoted service path vulnerability in Electronic Arts Dragon Age Origins 1.05's DAUpdaterSVC service. Attackers with local acce...
Jan 27, 2025This vulnerability allows local Windows users to escalate privileges to SYSTEM by exploiting an unquoted search path in Grafana Alloy. It affects Wind...
Sep 25, 2024This vulnerability in HPE MSA storage products allows attackers to gain elevated system privileges through the VSS Provider and CAPI Proxy software. I...
Apr 15, 2024This vulnerability allows an authenticated Windows user to escalate privileges by exploiting an unquoted service path in Intel Unite Client. Attackers...
Jun 9, 2021This vulnerability in TFTPD64-SE 4.64 involves an unquoted search path issue in the tftpd64_svc.exe service. It allows local attackers to potentially ...
Feb 17, 2023This vulnerability allows attackers with write access to a directory on the system drive to execute arbitrary code with SYSTEM privileges by exploitin...
Mar 5, 2026This vulnerability allows local attackers to escalate privileges to SYSTEM on Windows systems by exploiting unquoted service paths in Oki Electric Ind...
Feb 9, 2026This vulnerability allows attackers with file system access to execute arbitrary code through improper quotation in search paths in Eaton UPS Companio...
Dec 26, 2025This vulnerability in ELECOM Clone for Windows allows local privilege escalation through an unquoted service path. Attackers with write access to the ...
Dec 9, 2025CVE-2025-66461 is an unquoted service path vulnerability in GS Yuasa's FULLBACK Manager Pro software that allows local users with write permissions to...
Dec 8, 2025This CVE describes an unquoted search path vulnerability in PRI Driver software that could allow local authenticated attackers to escalate privileges....
Nov 11, 2025Sony Optical Disc Archive Software registers a Windows service with an unquoted file path, allowing local attackers with write permissions on the syst...
Nov 5, 2025This vulnerability allows local attackers with write permissions on the system drive root directory to escalate privileges to SYSTEM level by exploiti...
Nov 5, 2025This CVE describes an unquoted service path vulnerability in memoQ's Auto Update Service that allows local users to escalate privileges to SYSTEM leve...
Oct 29, 2025This vulnerability allows local attackers with write permissions on the system drive root directory to escalate privileges to SYSTEM level by exploiti...
Oct 23, 2025NAS Navigator2 Windows service has an unquoted file path vulnerability that allows local users with write permissions on the system drive root directo...
Oct 10, 2025This vulnerability involves an unquoted search path in the ThermoscanIP_Scrutation service, allowing attackers to execute arbitrary code by placing ma...
Jul 31, 2024CVE-2023-53912 is an unquoted service path vulnerability in USB Flash Drives Control 4.1.0.0 that allows local attackers to execute arbitrary code wit...
Dec 17, 2025This vulnerability in Sunshine game streaming software allows path interception attacks when terminating the service on Windows. Attackers can place m...
May 16, 2024This CVE describes an unquoted service path vulnerability in AnyDesk that allows local non-privileged users to escalate privileges to SYSTEM level. At...
Dec 11, 2025CVE-2024-58288 is an unquoted service path vulnerability in Genexus Protection Server 9.7.2.10 that allows local attackers to escalate privileges to L...
Dec 11, 2025This vulnerability allows local attackers with write permissions to directories preceding the UPSilon 2000 service executables to perform path interce...
Nov 26, 2025This vulnerability allows local attackers with filesystem write access to escalate privileges to SYSTEM level by exploiting an unquoted service path i...
Nov 26, 2025About CWE-428 (CWE-428)
Our database tracks 127 CVEs classified as CWE-428, with 2 rated critical and 107 rated high severity. The average CVSS score for CWE-428 vulnerabilities is 7.7.
External reference: View CWE-428 on MITRE CWE →
Monitor CWE-428 Vulnerabilities
Get alerted when new CWE-428 CVEs affect your infrastructure.
Start Monitoring Free