vendor:
DiskBoss Service
by:
Erick Galindo
7.8
CVSS
HIGH
Unquoted Service Path
427
CWE
Product Name: DiskBoss Service
Affected Version From: 12.2.18
Affected Version To: 12.2.18
Patch Exists: NO
Related CWE: N/A
CPE: //a:diskboss
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Pro x64 es
2021
DiskBoss Service 12.2.18 – ‘diskbsa.exe’ Unquoted Service Path
This vulnerability could permit executing code during startup or reboot with the escalated privileges. An attacker could exploit this vulnerability by placing a malicious executable in the same directory as the unquoted service path.
Mitigation:
Ensure that all services have a fully qualified path to the executable.