Vulnerabilities (CVE)

Filtered by CWE-428
Total 440 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-47787 1 Totalav 1 Totalav 2026-06-17 N/A 7.8 HIGH
TotalAV 5.15.69 contains an unquoted service path vulnerability in multiple system services running with LocalSystem privileges. Attackers can place malicious executables in specific unquoted path segments to potentially gain SYSTEM-level access by exploiting the service path configuration.
CVE-2021-47780 1 Macro-expert 1 Macro Expert 2026-06-17 N/A 7.8 HIGH
Macro Expert 4.7 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the improperly configured service path to inject malicious executables that will be run with LocalSystem permissions during service startup.
CVE-2021-47773 1 Dynojet 1 Power Core 2026-06-17 N/A 7.8 HIGH
Dynojet Power Core 2.3.0 contains an unquoted service path vulnerability in the DJ.UpdateService that allows local authenticated users to potentially execute code with elevated privileges. Attackers can exploit the unquoted binary path by placing malicious executables in the service's file path to gain Local System access.
CVE-2021-47767 1 10-strike 1 Network Inventory Explorer 2026-06-17 N/A 7.8 HIGH
10-Strike Network Inventory Explorer Pro 9.31 contains an unquoted service path vulnerability in the srvInventoryWebServer service running with LocalSystem privileges. Attackers can exploit the unquoted path by placing malicious executables in potential path segments to achieve privilege escalation and execute code with system-level permissions.
CVE-2021-47762 2026-06-17 N/A 7.8 HIGH
HTTPDebuggerPro 9.11 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables and gain elevated access to the system.
CVE-2021-47739 2026-06-17 N/A 8.4 HIGH
Epic Games Easy Anti-Cheat 4.0 contains an unquoted service path vulnerability that allows local non-privileged users to execute arbitrary code with elevated system privileges. Attackers can exploit the service configuration by inserting malicious code in the system root path that would execute with LocalSystem privileges during application startup.
CVE-2021-46368 1 Trigonesoft 1 Remote System Monitor 2026-06-17 4.6 MEDIUM 7.8 HIGH
TRIGONE Remote System Monitor 3.61 is vulnerable to an unquoted path service allowing local users to launch processes with elevated privileges.
CVE-2021-45819 1 Wordline 1 Hidccemonitorsvc 2026-06-17 7.2 HIGH 6.4 MEDIUM
Wordline HIDCCEMonitorSVC before v5.2.4.3 contains an unquoted service path which allows attackers to escalate privileges to the system level.
CVE-2021-45460 1 Siemens 2 Sicam Pq Analyzer, Sicam Pq Analyzer Firmware 2026-06-17 5.5 MEDIUM 8.1 HIGH
A vulnerability has been identified in SICAM PQ Analyzer (All versions < V3.18). A service is started by an unquoted registry entry. As there are spaces in this path, attackers with write privilege to those directories might be able to plant executables that will run in place of the legitimate process. Attackers might achieve persistence on the system ("backdoors") or cause a denial of service.
CVE-2021-43463 1 Ext2 File System Driver Project 1 Ext2 File System Driver 2026-06-17 7.2 HIGH 7.8 HIGH
An Unquoted Service Path vulnerability exists in Ext2Fsd v0.68 via a specially crafted file in the Ext2Srv Service executable service path.
CVE-2021-43460 1 Systemexplorer 1 System Explorer 2026-06-17 7.2 HIGH 7.8 HIGH
An Unquoted Service Path vulnerability exists in System Explorer 7.0.0 via via a specially crafted file in the SystemExplorerHelpService service executable path.
CVE-2021-43458 1 Vembu 1 Bdr Suite 2026-06-17 7.2 HIGH 7.8 HIGH
An Unquoted Service Path vulnerability exits in Vembu BDR 4.2.0.1 via a specially crafted file in the (1) hsflowd, (2) VembuBDR360Agent, or (3) VembuOffice365Agent service paths.
CVE-2021-43457 1 Bvpn 1 Bvpn 2026-06-17 7.2 HIGH 7.8 HIGH
An Unquoted Service Path vulnerability exists in bVPN 2.5.1 via a specially crafted file in the waselvpnserv service path.
CVE-2021-43456 1 Rumble Mail Server Project 1 Rumble Mail Server 2026-06-17 4.6 MEDIUM 7.8 HIGH
An Unquoted Service Path vulnerablility exists in Rumble Mail Server 0.51.3135 via via a specially crafted file in the RumbleService executable service path.
CVE-2021-43455 1 Freelan 1 Freelan 2026-06-17 7.2 HIGH 7.8 HIGH
An Unquoted Service Path vulnerability exists in FreeLAN 2.2 via a specially crafted file in the FreeLAN Service path.
CVE-2021-43454 1 Anytxt 1 Anytxt Searcher 2026-06-17 4.6 MEDIUM 7.8 HIGH
An Unquoted Service Path vulnerability exists in AnyTXT Searcher 1.2.394 via a specially crafted file in the ATService path. .
CVE-2021-42563 2 Microsoft, Ni 2 Windows, Ni Service Locator 2026-06-17 4.6 MEDIUM 7.8 HIGH
There is an Unquoted Service Path in NI Service Locator (nisvcloc.exe) in versions prior to 18.0 on Windows. This may allow an authorized local user to insert arbitrary code into the unquoted service path and escalate privileges.
CVE-2021-40683 2 Akamai, Microsoft 2 Enterprise Application Access, Windows 2026-06-17 4.4 MEDIUM 7.8 HIGH
In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquoted path may allow an attacker to hijack the flow of execution.
CVE-2021-35469 1 Lexmark 3 Printer Software G2, Printer Software G3, Printer Software G4 2026-06-17 7.2 HIGH 7.8 HIGH
The Lexmark Printer Software G2, G3 and G4 Installation Packages have a local escalation of privilege vulnerability due to a registry entry that has an unquoted service path.
CVE-2021-35231 1 Solarwinds 1 Kiwi Syslog Server 2026-06-17 4.6 MEDIUM 6.7 MEDIUM
As a result of an unquoted service path vulnerability present in the Kiwi Syslog Server Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or uninstall entry. Example vulnerable path: "Computer\HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Kiwi Syslog Server\Parameters\Application".