vendor:
SAPSprint
by:
Brian Rodriguez
5.5
CVSS
MEDIUM
Unquoted Service Path
428
CWE
Product Name: SAPSprint
Affected Version From: 7.6
Affected Version To: 7.6
Patch Exists: NO
Related CWE: CVE-2021-12345
CPE: sapsprint:7.60
Platforms Tested: Windows 10 Enterprise 64-bit
2021
SAPSprint 7.60 – ‘SAPSprint’ Unquoted Service Path
The SAPSprint service in SAPSprint.exe in SAPSprint 7.60 on Windows 10 Enterprise 64-bit allows local users to gain privileges via an unquoted service path vulnerability.
Mitigation:
To mitigate this vulnerability, ensure that the service executable path is properly quoted.