By weakness (CWE)

CWE-428: related vulnerabilities

CVEs classified under CWE-428. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

20 published vulnerabilities

  • CVE-2016-20085HIGH 7.8

    Realtek's High Definition Audio Driver version 6.0.1.6730 has a privilege escalation flaw rooted in how the Windows service is configured. The driver specifies its service path without quotation marks, meaning Windows may look for an executable in an unexpected location before finding the intended one. A local attacker with basic user privileges can exploit this by placing a malicious executable in one of those intermediate directories, then triggering a service restart to run their code with the highest system privileges (LocalSystem). This turns a low-impact design oversight into a serious lateral movement and persistence weapon.

  • CVE-2016-20086HIGH 7.8

    Vembu StoreGrid 4.0 has a privilege escalation vulnerability in two critical Windows services—RemoteBackup and RemoteBackup_webServer. These services are configured with unquoted file paths, which means an attacker with local system access can place a malicious executable in a location along the service's search path. When the service is restarted, Windows will execute the attacker's code instead of the legitimate service binary, granting the attacker full system-level (LocalSystem) privileges. This is a classic local privilege escalation attack that requires initial local access but yields complete system compromise.

  • CVE-2016-20087HIGH 7.8

    Fortitude HTTP version 1.0.4.0 contains a privilege escalation flaw rooted in how Windows constructs the path to the service executable. When a service path lacks quotation marks, Windows will attempt to execute the first unquoted portion of the path, creating an opportunity for a local attacker to plant a malicious executable in a directory that gets searched during service startup. If successful, that malicious code runs with SYSTEM-level privileges, giving an attacker complete control over the affected machine.

  • CVE-2016-20088HIGH 7.8

    Comodo Chromodo Browser version 52.15.25.664 has a privilege escalation vulnerability in its automatic update service. The service path is not properly quoted, allowing a local user with regular (non-admin) access to place a malicious program in the service directory. When the service restarts—either manually, during a system reboot, or during an update—the malicious program runs with full system privileges, giving an attacker complete control of the affected machine.

  • CVE-2016-20089HIGH 7.8

    Iperius Remote version 1.7.0 has a critical flaw in how it registers itself as a Windows service. If the software is installed in a folder path containing spaces (like C:\Program Files\Iperius Remote), an attacker with local access to the system can place a malicious executable in that path. When the service starts or the system reboots, Windows will execute the attacker's malicious file with SYSTEM-level privileges instead of the legitimate Iperius service, giving the attacker complete control over the machine.

  • CVE-2016-20090HIGH 7.8

    Comodo Dragon Browser versions up to 52.15.25.663 contain a local privilege escalation flaw in the DragonUpdater service. The service runs with SYSTEM-level permissions but uses an unquoted path to launch its executable. This allows a local attacker to place a malicious program in the service path that will execute with full system privileges when the service restarts or the system reboots. An attacker would need existing local access to exploit this, but the ability to run arbitrary code as SYSTEM makes this a significant security issue.

  • CVE-2016-20091HIGH 7.8

    Windows Firewall Control version 4.8.6.0 has a privilege escalation vulnerability caused by an unquoted service path in the wfcs.exe service executable. A local user on an affected system can place a malicious executable in a directory along the service's path and trigger execution of that malicious file with LocalSystem (full administrative) privileges when the service restarts or the system reboots. This is a classic file-placement attack that requires local access to the system but results in complete system compromise.

  • CVE-2016-20092HIGH 7.8

    NetDrive 2.6.12 is vulnerable to a privilege escalation attack through an unquoted service path. When the NetDrive service starts or the system reboots, an attacker with local access can place a malicious executable in the system root directory with a carefully crafted name. The Windows service loader will execute that malicious file with SYSTEM privileges instead of the legitimate NetDrive service, giving the attacker complete control over the affected system.

  • CVE-2016-20093HIGH 7.8

    Wise Care 365 version 4.27 and Wise Disk Cleaner version 9.29 contain a local privilege escalation vulnerability caused by improper quoting of service executable paths. An attacker with local access to the system can place a malicious executable in the system root directory with a name that matches part of the unquoted service path. When the affected service starts or the system reboots, Windows will execute the attacker's malicious file with SYSTEM privileges instead of the intended legitimate executable, granting the attacker complete control over the compromised system.

  • CVE-2016-20094HIGH 7.8

    AnyDesk 2.5.0 has a security flaw in how it registers its Windows service. The service path is not properly quoted, which means an attacker with local access to the system can place a malicious program in the system root directory. When AnyDesk starts or the system reboots, Windows will execute the attacker's malicious file instead of the legitimate AnyDesk service, giving it SYSTEM-level privileges—the highest level of access on Windows. This turns a local access vulnerability into a serious privilege escalation problem.

  • CVE-2016-20095HIGH 7.8

    Matrix42 Remote Control Host version 3.20.0031 has a privilege escalation vulnerability affecting its FastViewerRemoteService and FastViewerRemoteProxy services. An attacker with local system access can exploit an unquoted service path to place a malicious executable in the Program Files directory. When the service starts, it will execute the attacker's code with SYSTEM-level privileges, effectively giving an adversary complete control over the affected computer.

  • CVE-2019-25747HIGH 7.8

    Network Inventory Advisor version 5.0.26.0 contains a privilege escalation vulnerability stemming from how it installs its Windows service. The service binary path is not properly quoted, which means Windows will search for and execute the first matching file it encounters while parsing the path—a classic local privilege escalation vector. An authenticated attacker with limited user privileges can place a malicious executable in an intermediate directory along the service's search path, and when the service starts (either at boot or manual restart), their malicious code runs with full system-level privileges. This converts a local access account into full system compromise.

  • CVE-2020-37250HIGH 7.8

    TFTP Broadband version 4.3.0.1465 contains a flaw in how it specifies the path to its service executable. When Windows launches the tftpt.exe service, it does not properly quote the full file path, creating an opportunity for local attackers to place a malicious program in the Program Files directory with a name that will be executed first. If successful, this code runs with the highest system privileges (LocalSystem), potentially giving an attacker complete control over the machine.

  • CVE-2020-37251HIGH 7.8

    RealTimes Desktop Service version 18.1.4 has a privilege escalation vulnerability caused by an unquoted file path in its rpdsvc.exe service binary. A local attacker with standard user privileges can place a malicious executable in a directory along the unquoted service path and have it executed with system-level permissions when the service starts or the system reboots, effectively taking control of the affected machine.

  • CVE-2020-37252HIGH 7.8

    Realtek Audio Service version 1.0.0.55 has a vulnerability in how it specifies its executable path when starting as a system service. Because the path is not properly quoted, Windows will search for and execute the first matching file it finds in parent directories or the current working directory. An attacker with local access can exploit this by placing a malicious executable in a predictable location, causing it to run with the highest system privileges (LocalSystem) when the service starts or the system reboots.

  • CVE-2020-37253HIGH 7.8

    Winstep version 18.06.0096 contains a Windows service configuration flaw that allows local users to gain administrative control of affected systems. The vulnerability stems from an improperly quoted file path in the Winstep Xtreme Service startup configuration. An attacker with basic user access can place a malicious executable in the Program Files directory, which the service then runs with the highest Windows privilege level (LocalSystem) when it starts. This transforms a low-privilege account into a full system compromise vector.

  • CVE-2020-37254HIGH 7.8

    Wondershare PDFelement 5.2.9 has a Windows service configuration flaw that allows local users to escalate their privileges to system-level access. An attacker with a standard user account can place a specially crafted executable file in a predictable location on the system, then trigger a service restart or reboot to execute malicious code with the highest Windows privileges (LocalSystem). This is a classic privilege escalation attack enabled by improper path handling in the WsAppService component.

  • CVE-2021-47985HIGH 7.8

    Brother SAPSprint version 7.60 has a privilege escalation vulnerability where the Windows service that runs this software doesn't properly quote the full path to its executable file. An attacker with standard user access to a Windows system can place a malicious program in the Program Files directory that will be executed with full system privileges when the SAPSprint service starts. This turns a limited local account into one with complete control of the machine.

  • CVE-2022-50971HIGH 7.8

    Malwarebytes version 4.5 has a privilege escalation flaw in its service startup process. An attacker with basic local access can place a malicious program in specific system directories, and when Malwarebytes' service starts or the system reboots, that malicious code runs with the highest system privileges, giving the attacker complete control over the machine.

  • CVE-2023-54353HIGH 7.8

    Chromacam 4.0.3.0 has a vulnerability in how it registers and starts its PsyFrameGrabberService. The service path is not properly enclosed in quotes, meaning Windows will search for and execute the first matching executable it finds in the path sequence. An attacker with local write access can place a malicious executable (named Program.exe or PsyFrameGrabberService.exe) in a directory that Windows checks before the legitimate service, causing their malicious code to run with the highest system privileges (LocalSystem) each time the system boots or the service restarts.