vendor:
ATKGFNEX
by:
Cyril Vallicari
7,2
CVSS
HIGH
Privilege Escalation Unquoted Service Path
N/A
CWE
Product Name: ATKGFNEX
Affected Version From: 1.0.11.1
Affected Version To: 1.0.11.1
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 x64 SP1
2016
ATKGFNEXSrv ATKGFNEX- Privilege Escalation Unquoted Service Path vulnerability
The application suffers from an unquoted service path issue impacting the service 'ATKGFNEXSrv (GFNEXSrv.exe)' deployed as part of ATKGFNEX. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with system privileges.
Mitigation:
N/A