vendor:
Alps Pointing-device Controller
by:
Mario Rodriguez
5.5
CVSS
MEDIUM
Unquoted Service Path
428
CWE
Product Name: Alps Pointing-device Controller
Affected Version From: 8.1202.1711.04
Affected Version To: 8.1202.1711.04
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 Home x64 Spanish
2019
Alps Pointing-device Controller 8.1202.1711.04 – ‘ApHidMonitorService’ Unquoted Service Path
The Alps Pointing-device controller installs a service with an unquoted path which could be used as a local privilege escalation vulnerability. To exploit this vulnerability, an executable file could be placed in the path of the service and after rebooting the system or restarting the service the malicious code will be executed with elevated privileges.
Mitigation:
The vendor should update the installation process to include properly quoted service paths to prevent this vulnerability.