vendor:
ASUS HM Com Service
by:
Olimpia Saucedo
7.5
CVSS
HIGH
Unquoted Service Path
428
CWE
Product Name: ASUS HM Com Service
Affected Version From: 1.00.31
Affected Version To: 1.00.31
Patch Exists: NO
Related CWE:
CPE: a:asus:hm_com_service:1.00.31
Platforms Tested: Windows
2019
ASUS HM Com Service 1.00.31 – ‘asHMComSvc’ Unquoted Service Path
The application suffers from an unquoted service path issue impacting the service 'ASUS HM Com Service (aaHMSvc.exe)' related to the Asus Motherboard Utilities. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with system privileges.
Mitigation:
To mitigate this vulnerability, the vendor should update the service path to include quotes around the file path.