vendor:
Alps HID Monitor Service
by:
Héctor Gabriel Chimecatl Hernández
7.8
CVSS
HIGH
Unquoted Service Path
835
CWE
Product Name: Alps HID Monitor Service
Affected Version From: 8.1.0.10
Affected Version To: 8.1.0.10
Patch Exists: NO
Related CWE: N/A
CPE: a:alps:alps_hid_monitor_service
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Home Single Language x64 Esp
2019
Alps HID Monitor Service 8.1.0.10 – ‘ApHidMonitorService’ Unquote Service Path
The Alps HID Monitor Service 8.1.0.10 is vulnerable to an unquoted service path vulnerability. This vulnerability can be exploited by an attacker to gain elevated privileges on the system. The attacker can use the 'wmic' command to discover the unquoted service path and then use the 'sc qc' command to view the service configuration.
Mitigation:
Ensure that all services have their paths quoted properly. Also, ensure that all services are running with the least privileges necessary.