vendor:
Power Core
by:
Pedro Sousa Rodrigues
7.2
CVSS
HIGH
Unquoted Service Path
426
CWE
Product Name: Power Core
Affected Version From: 2.3.0 (Build 303)
Affected Version To: 2.3.0 (Build 303)
Patch Exists: NO
Related CWE:
CPE: a:dynojet:power_core:2.3.0
Platforms Tested: Windows 10 Version 21H1 (OS Build 19043.1320)
2021
Dynojet Power Core 2.3.0 – Unquoted Service Path
A successful attempt would require the local user to be able to insert their code in the system root path (depending on the installation path). The service might be executed manually by any Authenticated user. If successful, the local user's code would execute with the elevated privileges of Local System.
Mitigation:
Ensure that all services have a fully qualified path to the executable.