vendor:
UTPS Software
by:
Dhruv Shah
6,7
CVSS
MEDIUM
Unquoted Service Path
426
CWE
Product Name: UTPS Software
Affected Version From: UTPS-V200R003B015D16SPC00C983
Affected Version To: UTPS-V200R003B015D16SPC00C983
Patch Exists: Yes
Related CWE: CVE-2016-8769
CPE: a:huawei:utps
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP, Windows 7-10 x86/x64
2016
Unquoted Service Path Vulnerability in Huawei UTPS Software
Huawei UTPS Software is the core software that is bundled with the Internet Dongles, it provides it dongles to companies like Airtel, TATA Photon. This is the software that installs itself for the Dongle to run on the attached machine. It installs as a service ('Photon. RunOUC') and ('Airtel. RunOuc') with an unquoted service path running with SYSTEM privileges. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system.
Mitigation:
The vendor has released a patch for this vulnerability.