Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CWE-428 (未经引用的搜索路径或元素) — Vulnerability Class 329

329 vulnerabilities classified as CWE-428 (未经引用的搜索路径或元素). AI Chinese analysis included.

CWE-428 represents a critical input validation weakness where software constructs search paths containing unquoted elements with whitespace or separators. This flaw typically enables privilege escalation attacks, as attackers can exploit the ambiguous parsing by placing malicious executables in parent directories, such as creating a file named "Program.exe" within a system folder. When a privileged process executes a command like WinExec without proper quoting, it may inadvertently run the attacker-controlled file instead of the intended target. Developers prevent this vulnerability by strictly enforcing quoted strings around all path elements in command-line arguments. Additionally, implementing strict input validation and avoiding dynamic path construction from untrusted sources ensures that the operating system correctly interprets the intended file location, thereby neutralizing the risk of unintended resource access or code execution.

MITRE CWE Description
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path. If a malicious individual has access to the file system, it is possible to elevate privileges by inserting such a file as "C:\Program.exe" to be run by a privileged program making use of WinExec.
Common Consequences (1)
Confidentiality, Integrity, Availability Execute Unauthorized Code or Commands
Mitigations (3)
Implementation Properly quote the full search path before executing a program on the system.
Implementation Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does. When performing input validation, consider all potentially relevant properties, including length, type of input, the full range…
Implementation Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous inputs after they have been checked.
Examples (1)
The following example demonstrates the weakness.
UINT errCode = WinExec( "C:\\Program Files\\Foo\\Bar", SW_SHOW );
Bad · C
CVE ID Title CVSS Severity Published
CVE-2026-66839 Integrated NetKids iMark 权限许可和访问控制问题漏洞 — NetKids iMark 8.4 High 2026-08-05
CVE-2026-18755 GV-ASManager DLL hijacking vulnerability — GV-ASManager 7.3 High 2026-08-04
CVE-2026-9128 Studio 5000 Logix Designer® – Multiple Vulnerabilities — Studio 5000 Logix Designer - - 2026-07-14
CVE-2026-8864 HP Fan Control App – Potential Escalation of Privilege — HP Fan Control App - - 2026-06-30
CVE-2025-71326 AVAST Antivirus 25.11 Unquoted Service Path Privilege Escalation — AVAST Antivirus 7.8 High 2026-06-19
CVE-2023-54353 Chromacam 4.0.3.0 Unquoted Service Path Privilege Escalation — Chromacam 7.8 High 2026-06-19
CVE-2021-47985 Brother SAPSprint 7.60 Unquoted Service Path Privilege Escalation — SAPSprint 7.8 High 2026-06-19
CVE-2022-50971 Malwarebytes 4.5 Unquoted Service Path Privilege Escalation — Malwarebytes 7.8 High 2026-06-19
CVE-2020-37254 Wondershare PDFelement 5.2.9 Privilege Escalation via Unquoted Service Path — PDFelement 7.8 High 2026-06-19
CVE-2020-37252 Realtek Audio Service 1.0.0.55 Unquoted Service Path Privilege Escalation — Realtek Audio Service 7.8 High 2026-06-19
CVE-2020-37253 Winstep 18.06.0096 Unquoted Service Path Privilege Escalation — Winstep 7.8 High 2026-06-19
CVE-2020-37251 RealTimes Desktop Service 18.1.4 Unquoted Service Path Privilege Escalation — RealTimes Desktop Service 7.8 High 2026-06-19
CVE-2020-37250 TFTP Broadband 4.3.0.1465 Unquoted Service Path Privilege Escalation — TFTP Broadband 7.8 High 2026-06-19
CVE-2019-25747 Network Inventory Advisor 5.0.26.0 Unquoted Service Path Privilege Escalation — Network Inventory Advisor 7.8 High 2026-06-19
CVE-2016-20095 Matrix42 Remote Control Host 3.20.0031 Unquoted Path Privilege Escalation — Matrix42 Remote Control Host 7.8 High 2026-06-19
CVE-2016-20094 AnyDesk 2.5.0 Unquoted Service Path Elevation of Privilege — AnyDesk 7.8 High 2026-06-19
CVE-2016-20093 Wise Care 365 4.27 and Wise Disk Cleaner 9.29 Unquoted Service Path Privilege Escalation — Wise Care 365 7.8 High 2026-06-19
CVE-2016-20092 NetDrive 2.6.12 Unquoted Service Path Elevation of Privilege — NetDrive 7.8 High 2026-06-19
CVE-2016-20091 Windows Firewall Control 4.8.6.0 Unquoted Service Path Privilege Escalation — Windows Firewall Control 7.8 High 2026-06-19
CVE-2016-20089 Iperius Remote 1.7.0 Unquoted Service Path Elevation of Privilege — Iperius Remote 7.8 High 2026-06-19
CVE-2016-20090 Comodo Dragon Browser 52.15.25.663 Privilege Escalation via Unquoted Service Path — Dragon Browser 7.8 High 2026-06-19
CVE-2016-20088 Comodo Chromodo Browser 52.15.25.664 Unquoted Service Path Privilege Escalation — Chromodo Browser 7.8 High 2026-06-19
CVE-2016-20087 Fortitude HTTP 1.0.4.0 Unquoted Service Path Elevation of Privilege — Fortitude HTTP 7.8 High 2026-06-19
CVE-2016-20086 Vembu StoreGrid 4.0 Unquoted Service Path Privilege Escalation — Vembu StoreGrid 7.8 High 2026-06-19
CVE-2016-20085 Realtek High Definition Audio Driver 6.0.1.6730 Privilege Escalation — Realtek High Definition Audio Driver 7.8 High 2026-06-19
CVE-2026-25865 Punto Switcher 4.5.0.583 Unquoted Search Path via WinExec — Punto Switcher 7.8 High 2026-06-18
CVE-2021-47974 VX Search 13.5.28 Unquoted Service Path Privilege Escalation — VX Search 7.8 High 2026-05-16
CVE-2020-37247 Kite 4.2.0.1 U1 Unquoted Service Path Privilege Escalation — Kite 7.8 High 2026-05-16
CVE-2020-37232 Advanced System Care Service 13.0.0.157 Unquoted Service Path Privilege Escalation — Advanced System Care Service 7.8 High 2026-05-16
CVE-2020-37231 Privacy Drive 3.17.0 Unquoted Service Path Privilege Escalation — Privacy Drive 7.8 High 2026-05-16

Vulnerabilities classified as CWE-428 (未经引用的搜索路径或元素) represent 329 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.