vendor:
DiskBoss
by:
Mohammed Alshehri
7.2
CVSS
HIGH
Unquoted Service Path
73
CWE
Product Name: DiskBoss
Affected Version From: v11.7.28
Affected Version To: v11.7.28
Patch Exists: NO
Related CWE: N/A
CPE: a:diskboss:diskboss
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Microsoft Windows Server 2019 Standard 10.0.17763 N/A Build 17763
2020
DiskBoss v11.7.28 – Multiple Services Unquoted Service Path
DiskBoss v11.7.28 and its related products are vulnerable to Unquoted Service path. Any low privileged user can elevate their privileges using any of these services.
Mitigation:
Ensure that all services have a fully qualified path to the executable.