Show filters
28 Total Results
Displaying 1-10 of 28
Sort by:
Attacker Value
Unknown
CVE-2021-21292
Disclosure Date: February 02, 2021 (last updated February 22, 2025)
Traccar is an open source GPS tracking system. In Traccar before version 4.12 there is an unquoted Windows binary path vulnerability. Only Windows versions are impacted. Attacker needs write access to the filesystem on the host machine. If Java path includes a space, then attacker can lift their privilege to the same as Traccar service (system). This is fixed in version 4.12.
0
Attacker Value
Unknown
CVE-2020-5147
Disclosure Date: January 09, 2021 (last updated February 22, 2025)
SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated privileges in the host operating system. This vulnerability impact SonicWall NetExtender Windows client version 10.2.300 and earlier.
0
Attacker Value
Unknown
CVE-2020-27645
Disclosure Date: December 29, 2020 (last updated February 22, 2025)
The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.Metrics.exe. This may allow remote authenticated users and local users to gain elevated privileges.
0
Attacker Value
Unknown
CVE-2020-27644
Disclosure Date: December 29, 2020 (last updated February 22, 2025)
The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.Metrics.exe. This may allow remote authenticated users and local users to gain elevated privileges by placing a malicious cryptbase.dll file in %WINDIR%\Temp\.
0
Attacker Value
Unknown
CVE-2020-35152
Disclosure Date: December 11, 2020 (last updated February 22, 2025)
Cloudflare WARP for Windows allows privilege escalation due to an unquoted service path. A malicious user or process running with non-administrative privileges can become an administrator by abusing the unquoted service path issue. Since version 1.2.2695.1, the vulnerability was fixed by adding quotes around the service's binary path. This issue affects Cloudflare WARP for Windows, versions prior to 1.2.2695.1.
0
Attacker Value
Unknown
CVE-2020-28209
Disclosure Date: November 19, 2020 (last updated February 22, 2025)
A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user who has write permission on at least one of the subfolders of the Connect Agent service binary path, being able to gain the privilege of the user who started the service. By default, the Enterprise Server and Enterprise Central is always installed at a location requiring Administrator privileges so the vulnerability is only valid if the application has been installed on a non-secure location.
0
Attacker Value
Unknown
CVE-2020-7331
Disclosure Date: November 11, 2020 (last updated February 22, 2025)
Unquoted service executable path in McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows local users to cause a denial of service and malicious file execution via carefully crafted and named executable files.
0
Attacker Value
Unknown
CVE-2020-15261
Disclosure Date: October 19, 2020 (last updated February 22, 2025)
On Windows the Veyon Service before version 4.4.2 contains an unquoted service path vulnerability, allowing locally authenticated users with administrative privileges to run malicious executables with LocalSystem privileges. Since Veyon users (both students and teachers) usually don't have administrative privileges, this vulnerability is only dangerous in anyway unsafe setups. The problem has been fixed in version 4.4.2. As a workaround, the exploitation of the vulnerability can be prevented by revoking administrative privileges from all potentially untrustworthy users.
0
Attacker Value
Unknown
CVE-2020-7316
Disclosure Date: October 07, 2020 (last updated February 22, 2025)
Unquoted service path vulnerability in McAfee File and Removable Media Protection (FRP) prior to 5.3.0 allows local users to execute arbitrary code, with higher privileges, via execution and from a compromised folder. This issue may result in files not being encrypted when a policy is triggered.
0
Attacker Value
Unknown
CVE-2020-10051
Disclosure Date: September 09, 2020 (last updated February 22, 2025)
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). Multiple services of the affected application are executed with SYSTEM privileges while the call path is not quoted. This could allow a local attacker to inject arbitrary commands that are execeuted instead of the legitimate service.
0