vendor:
IOTransfer
by:
BLAY ABU SAFIAN (Inveteck Global)
7.8
CVSS
HIGH
Unquoted Service Path
428
CWE
Product Name: IOTransfer
Affected Version From: IOTransfer V4
Affected Version To: IOTransfer V4
Patch Exists: NO
Related CWE: CVE-2022-37197
CPE: a:iobit:iotransfer:4
Platforms Tested: Microsoft Windows Server 2019 Standard Evaluation
2022
IOTransfer V4 – Unquoted Service Path
The IOTransfer V4 software on Microsoft Windows Server 2019 Standard Evaluation allows local users to gain privileges via an unquoted service path vulnerability.
Mitigation:
To mitigate this vulnerability, the vendor should ensure that the service path is quoted correctly in the software code.