vendor:
SAntivirus
by:
Mara Ramirez
7.8
CVSS
HIGH
Unquoted Service Path
426
CWE
Product Name: SAntivirus
Affected Version From: 10.0.21.61
Affected Version To: 10.0.21.61
Patch Exists: NO
Related CWE: N/A
CPE: a:digital_communications:santivirus:10.0.21.61
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Home Single Languaje
2020
SAntivirus IC 10.0.21.61 – ‘SAntivirusIC’ Unquoted Service Path
The SAntivirus IC 10.0.21.61 software contains an Unquoted Service Path vulnerability. This vulnerability can be exploited by an attacker to gain elevated privileges on the system. The vulnerability exists because the software does not properly quote the path to the service executable. An attacker can exploit this vulnerability by placing malicious code in the same directory as the service executable and then executing it with elevated privileges.
Mitigation:
Ensure that all service paths are properly quoted. Additionally, ensure that all services are running with the least privileges necessary.