vendor:
MasterPlus
by:
Damian Semon Jr (Blue Team Alpha)
7.2
CVSS
HIGH
Unquoted Service Path
787
CWE
Product Name: MasterPlus
Affected Version From: 1.8.2005
Affected Version To: 1.8.2005
Patch Exists: NO
Related CWE:
CPE: a:coolermaster:masterplus:1.8.5
Platforms Tested: Windows 10 64x
2022
CoolerMaster MasterPlus 1.8.5 – ‘MPService’ Unquoted Service Path
A successful exploit of this vulnerability could allow a threat actor to execute code during startup or reboot with System privileges. Drop payload 'Program.exe' in C: and restart service or computer to trigger.
Mitigation:
Ensure that all services have a fully qualified path to the executable.