vendor:
iFunbox
by:
Julio Aviña
N/A
CVSS
N/A
Unquoted Service Path
Unknown
CWE
Product Name: iFunbox
Affected Version From: 4.2
Affected Version To: 4.2
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested: Windows 10 Pro x64
2021
iFunbox 4.2 – ‘Apple Mobile Device Service’ Unquoted Service Path
A successful attempt to exploit this vulnerability requires the attacker to insert an executable file into the service path undetected by the OS or some security application. When restarting the service or the system, the inserted executable will run with elevated privileges.
Mitigation:
Unknown