vendor:
GCafé 3.0
by:
Doan Nguyen (4ll4u)
5.5
CVSS
MEDIUM
Unquoted Service Path
428
CWE
Product Name: GCafé 3.0
Affected Version From: 3
Affected Version To: 3
Patch Exists: NO
Related CWE:
CPE: a:gcafe:gc3
Platforms Tested: Windows 7, Windows 10, Windows XP
2019
_GCafé 3.0 – ‘gbClienService’ Unquoted Service Path
The gbClienService service in GCafé 3.0 has an unquoted service path vulnerability, which could allow an attacker to escalate privileges on Windows systems.
Mitigation:
The vendor should release a patched version of the software where the service path is quoted correctly. Users should update to the latest version of GCafé 3.0 or apply the vendor-supplied patch.