vendor:
Tftpd32_SE
by:
Ismael Nava
5.5
CVSS
MEDIUM
Unquoted Service Path
CWE
Product Name: Tftpd32_SE
Affected Version From: 4.6
Affected Version To: 4.6
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Microsoft Windows 10 Home 64 bits
2022
Tftpd32_SE 4.60 – ‘Tftpd32_svc’ Unquoted Service Path
The Tftpd32_SE 4.60 software on Microsoft Windows 10 Home 64 bits is vulnerable to an unquoted service path vulnerability. This can allow an attacker to escalate privileges by placing a malicious executable in the path. The vulnerability was discovered by Ismael Nava.
Mitigation:
The vendor has not provided a patch or mitigation for this vulnerability.