vendor:
Cain & Abel
by:
Aryan Chehreghani
7.5
CVSS
HIGH
Unquoted Service Path
428
CWE
Product Name: Cain & Abel
Affected Version From: 4.9.56
Affected Version To: 4.9.56
Patch Exists: NO
Related CWE:
CPE: cain-and-abel:4.9.56
Platforms Tested: Windows 10 x64
2022
Cain & Abel 4.9.56 – Unquoted Service Path
The Cain & Abel version 4.9.56 software on Windows 10 x64 is vulnerable to an unquoted service path vulnerability. The 'Abel' service has a binary path name that is not properly quoted, which could allow an attacker to escalate privileges and execute arbitrary code with the permissions of the LocalSystem account.
Mitigation:
To mitigate this vulnerability, the vendor should update the software to quote the binary path name properly. Users can also manually quote the binary path name to prevent exploitation.