vendor:
Filmora
by:
Thurein Soe
7.8
CVSS
HIGH
Unquoted Service Paths Privilege Escalation
428
CWE
Product Name: Filmora
Affected Version From: Filmora 12 (Build 1.0.0.7)
Affected Version To: Filmora 12 (Build 1.0.0.7)
Patch Exists: NO
Related CWE: CVE-2023-31747
CPE: a:wondershare:filmora:12.2.1.2088
Platforms Tested: Windows 10 (Version 10.0.19045.2965)
2023
Filmora 12 version (Build 1.0.0.7) – Unquoted Service Paths Privilege Escalation
Wondershare NativePush Build 1.0.0.7, which is part of Filmora 12 (Build 12.2.1.2088), is vulnerable to unquoted service paths. This vulnerability allows a local user to escalate their privileges to local admin by replacing the affected executable.
Mitigation:
The vendor should update the service to use quoted service paths to prevent privilege escalation.