vendor:
USB Flash Drives Control
by:
Jeffrey Bencteux
7.5
CVSS
HIGH
Unquoted Service Path
428
CWE
Product Name: USB Flash Drives Control
Affected Version From: 4.1.0.0
Affected Version To: 4.1.0.0
Patch Exists: NO
Related CWE:
CPE: a:binisoft:usb_flash_drives_control:4.1.0.0
Platforms Tested: Microsoft Windows 11 Pro
2023
USB Flash Drives Control 4.1.0.0 – Unquoted Service Path
The USB Flash Drives Control software version 4.1.0.0 is vulnerable to an unquoted service path vulnerability. This allows an attacker to gain elevated privileges by placing a malicious executable in a directory with spaces in its name.
Mitigation:
To mitigate this vulnerability, the vendor should update the software to use quoted paths for the service binary. Users should also ensure that their system is up-to-date with the latest security patches.