Cyber Resilience

CWE · MITRE source

CWE-428Unquoted Search Path or Element

Abstraction: Base · CVEs in our corpus: 452

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

If a malicious individual has access to the file system, it is possible to elevate privileges by inserting such a file as "C:\Program.exe" to be run by a privileged program making use of WinExec.

Last updated: 20 August 2026 13:14 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.PS-06
  • SA-11 Developer Testing and Evaluation
  • SA-8 Security and Privacy Engineering Principles
  • SA-15 Development Process, Standards, and Tools
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2023-38408 9.99.80.79702023-07-20
CVE-2019-17658 7.79.80.02182020-03-12
CVE-2020-9292 7.69.80.01552020-06-04
CVE-2019-8459 7.59.80.01192019-06-20
CVE-2022-36344 7.49.80.00832022-08-16
CVE-2022-50935 7.29.80.00372026-01-13
CVE-2024-24722 6.99.10.00612024-02-19
CVE-2020-27644 6.88.80.01162020-12-29
CVE-2020-27645 6.88.80.01232020-12-29
CVE-2020-15261 6.68.00.11252020-10-19
CVE-2023-27298 6.68.80.00652023-05-10
CVE-2018-10619 6.37.80.02762018-06-07
CVE-2020-5569 6.38.40.00362020-04-20
CVE-2021-45460 6.38.10.00832022-01-11
CVE-2017-13993 6.27.80.01762017-10-05
CVE-2019-18915 6.27.80.01482020-02-13
CVE-2023-53965 6.28.40.00232025-12-22
CVE-2022-50901 6.28.40.00242026-01-13
CVE-2022-50903 6.28.40.00242026-01-13
CVE-2016-5793 6.18.80.00382016-09-24
CVE-2018-4873 6.17.80.01292018-05-19
CVE-2018-16183 6.17.80.01332019-01-09
CVE-2019-6008 6.17.80.01262019-12-26
CVE-2020-14521 6.18.30.01272022-02-11
CVE-2022-23909 6.17.80.01032022-04-05