vendor:
ActiveFax Server
by:
Cakes
7.8
CVSS
HIGH
Unquoted Service Path
428
CWE
Product Name: ActiveFax Server
Affected Version From: ActiveFax Server 6.92 Build 0316
Affected Version To: ActiveFax Server 6.92 Build 0316
Patch Exists: NO
Related CWE:
CPE: a:actfax:activefax_server:6.92:build_0316
Platforms Tested: Windows 10
2019
ActiveFax Server 6.92 Build 0316 – ‘ActiveFaxServiceNT’ Unquoted Service Path
The ActiveFax Server 6.92 Build 0316 software has an unquoted service path vulnerability. This vulnerability could allow an attacker to escalate privileges and execute arbitrary code by placing a malicious executable in the path.
Mitigation:
To mitigate this vulnerability, it is recommended to update to the latest version of ActiveFax Server and ensure that the service path is properly quoted.