vendor:
BRAdmin Professional
by:
Metin Yunus Kandemir
7.8
CVSS
HIGH
Unquoted Service Path
78
CWE
Product Name: BRAdmin Professional
Affected Version From: 3.75.0000
Affected Version To: 3.75.0000
Patch Exists: YES
Related CWE: N/A
CPE: a:brother:bradmin_professional:3.75.0000
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2021
BRAdmin Professional 3.75 – ‘BRA_Scheduler’ Unquoted Service Path
This software allows system administrators to view and control the status of their networked Brother and most other SNMP compliant printing devices. If a user can insert a executable which is called as 'BRAdmin' under the 'C:Program Files (x86)Brother', local system privileges could be obtained by the user.
Mitigation:
Ensure that all services have a fully qualified path to the executable, and that the path is enclosed in quotes.