vendor:
Encrypto
by:
Ismael Nava
6.2
CVSS
MEDIUM
Unquoted Service Path
428
CWE
Product Name: Encrypto
Affected Version From: 1.0.1
Affected Version To: 1.0.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 64-bit
2020
MacPaw Encrypto 1.0.1 – ‘Encrypto Service’ Unquoted Service Path
The MacPaw Encrypto version 1.0.1 is vulnerable to an unquoted service path vulnerability. This vulnerability allows an attacker to escalate privileges by placing a malicious executable in a higher privileged directory with the same name as the service executable. When the service is started, the malicious executable will be executed instead. This can lead to remote code execution or other malicious activities.
Mitigation:
To mitigate this vulnerability, it is recommended to update to the latest version of MacPaw Encrypto or ensure that the service path is quoted correctly. Additionally, users should regularly update their operating systems and use strong passwords for their user accounts.