vendor:
DigitalPersona
by:
Teresa Q
7.8
CVSS
HIGH
Unquoted Service Path
426
CWE
Product Name: DigitalPersona
Affected Version From: 5.1.0.656
Affected Version To: 5.1.0.656
Patch Exists: NO
Related CWE: N/A
CPE: a:hid_global:digitalpersona:5.1.0.656
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Home x64 es
2020
DigitalPersona 5.1.0.656 ‘DpHostW’ – Unquoted Service Path
DigitalPersona 5.1.0.656 contains an Unquoted Service Path vulnerability in the DpHostW.exe service. This can be exploited by a local attacker to gain elevated privileges on the affected system.
Mitigation:
Ensure that all services have a fully qualified path to the executable. This can be done by using the Services MMC snap-in, or by using the sc.exe command line utility.