Show filters
38 Total Results
Displaying 1-10 of 38
Sort by:
Attacker Value
Unknown

CVE-2021-40683

Disclosure Date: October 04, 2021 (last updated February 23, 2025)
In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquoted path may allow an attacker to hijack the flow of execution.
Attacker Value
Unknown

CVE-2021-23879

Disclosure Date: September 03, 2021 (last updated February 22, 2025)
Unquoted service path vulnerability in McAfee Endpoint Product Removal (EPR) Tool prior to 21.2 allows local administrators to execute arbitrary code, with higher-level privileges, via execution from a compromised folder. The tool did not enforce and protect the execution path. Local admin privileges are required to place the files in the required location.
Attacker Value
Unknown

CVE-2020-11632

Disclosure Date: July 15, 2021 (last updated February 23, 2025)
The Zscaler Client Connector prior to 2.1.2.150 did not quote the search path for services, which allows a local adversary to execute code with system privileges.
Attacker Value
Unknown

CVE-2021-35056

Disclosure Date: July 15, 2021 (last updated February 23, 2025)
Unisys Stealth 5.1 before 5.1.025.0 and 6.0 before 6.0.055.0 has an unquoted Windows search path for a scheduled task. An unintended executable might run.
Attacker Value
Unknown

CVE-2021-35469

Disclosure Date: July 14, 2021 (last updated February 23, 2025)
The Lexmark Printer Software G2, G3 and G4 Installation Packages have a local escalation of privilege vulnerability due to a registry entry that has an unquoted service path.
Attacker Value
Unknown

CVE-2021-0112

Disclosure Date: June 09, 2021 (last updated February 22, 2025)
Unquoted service path in the Intel Unite(R) Client for Windows before version 4.2.25031 may allow an authenticated user to potentially enable an escalation of privilege via local access.
Attacker Value
Unknown

CVE-2020-22809

Disclosure Date: May 10, 2021 (last updated February 22, 2025)
In Windscribe v1.83 Build 20, 'WindscribeService' has an Unquoted Service Path that facilitates privilege escalation.
Attacker Value
Unknown

CVE-2021-31776

Disclosure Date: April 29, 2021 (last updated February 22, 2025)
Aviatrix VPN Client before 2.14.14 on Windows has an unquoted search path that enables local privilege escalation to the SYSTEM user, if the machine is misconfigured to allow unprivileged users to write to directories that are supposed to be restricted to administrators.
Attacker Value
Unknown

CVE-2021-31553

Disclosure Date: April 22, 2021 (last updated February 22, 2025)
An issue was discovered in the CheckUser extension for MediaWiki through 1.35.2. MediaWiki usernames with trailing whitespace could be stored in the cu_log database table such that denial of service occurred for certain CheckUser extension pages and functionality. For example, the attacker could turn off Special:CheckUserLog and thus interfere with usage tracking.
Attacker Value
Unknown

CVE-2021-27608

Disclosure Date: April 14, 2021 (last updated February 22, 2025)
An unquoted service path in SAPSetup, version - 9.0, could lead to privilege escalation during the installation process that is performed when an executable file is registered. This could further lead to complete compromise of confidentiality, Integrity and Availability.