vendor:
BarcodeOCR
by:
Daniel Bertoni
7.2
CVSS
HIGH
Unquoted Service Path
426
CWE
Product Name: BarcodeOCR
Affected Version From: 19.3.6
Affected Version To: 19.3.6
Patch Exists: NO
Related CWE: N/A
CPE: a:barcode-ocr:barcodeocr:19.3.6
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows Server 2016, Windows 10
2020
BarcodeOCR 19.3.6 – ‘BarcodeOCR’ Unquoted Service Path
A successful attempt to exploit this vulnerability could allow to execute code during startup or reboot with the elevated privileges.
Mitigation:
Ensure that all services have a fully qualified path name and that the path is enclosed in quotes.