vendor:
ArcServe UDP Standard Edition for Windows, TRIAL
by:
Unknown
5.5
CVSS
MEDIUM
Unquoted Service Path Privilege Escalation
427
CWE
Product Name: ArcServe UDP Standard Edition for Windows, TRIAL
Affected Version From: 6.0.3792 Update 2 Build 516
Affected Version To: 6.0.3792 Update 2 Build 516
Patch Exists: NO
Related CWE:
CPE: a:arcserve:arcserve_udp_standard_edition:6.0.3792_update_2_build_516
Platforms Tested: Windows
2016
ArcServe UDP – Unquoted Service Path Privilege Escalation
ArcServe UDP for Windows installs various services. One of them is the 'Arcserve UDP Update Service (CAARCUpdateSvc)' running as SYSTEM. This particular service has an insecurely quoted path. An attacker with write permissions on the root-drive or directory in the search path could place a malicious binary and elevate privileges.
Mitigation:
To mitigate this vulnerability, ArcServe should update the service path to use properly quoted paths.