vendor:
Kiwi CatTools
by:
Mert DAS
8.8
CVSS
HIGH
Unquoted Service Path
426
CWE
Product Name: Kiwi CatTools
Affected Version From: 3.11.2008
Affected Version To: 3.11.2008
Patch Exists: No
Related CWE:
CPE: a:solarwinds:kiwi_cattools:3.11.8
Platforms Tested: Windows 10
2021
SolarWinds Kiwi CatTools 3.11.8 – Unquoted Service Path
Unquoted Service Path is a vulnerability that occurs when the path of a service contains spaces and is not surrounded by quotation marks. This can allow an attacker to insert their own malicious code in the system root path undetected by the OS or other security applications, which can be executed with the elevated privileges of the application.
Mitigation:
To mitigate this vulnerability, administrators should ensure that all service paths are properly quoted.