Advanced Host Monitor > 12.56 – Unquoted Service Path
An unquoted service path vulnerability has been discovered in Advanced Host Monitor version > 12.56 affecting the executable "C:Program Files (x86)HostMonitorRMA-Winrma_active.exe". This vulnerability occurs when the service's path is misconfigured, allowing an attacker to run a malicious file instead of the legitimate executable associated with the service. An attacker with local user privileges could exploit this vulnerability to replace the legitimate RMA-Winrma_active.exe service executable with a malicious file of the same name and located in a directory that has a higher priority than the legitimate directory. That way, when the service starts, it will run the malicious file instead of the legitimate executable, allowing the attacker to execute arbitrary code, gain unauthorized access to the compromised system, or stop the service from functioning.