vendor:
RealTimes
by:
Erick Galindo
8.8
CVSS
HIGH
Unquoted Service Path
426
CWE
Product Name: RealTimes
Affected Version From: 18.1.4
Affected Version To: 18.1.4
Patch Exists: No
Related CWE: N/A
CPE: a:realnetworks:realtimes
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 Enterprise SP1 x64 es
2020
RealTimes Desktop Service 18.1.4 – ‘rpdsvc.exe’ Unquoted Service Path
This vulnerability could permit executing code during startup or reboot with the escalated privileges.
Mitigation:
Ensure that all services have a fully qualified path to the executable.