vendor:
FreeSSHd
by:
boku
7.2
CVSS
HIGH
Unquoted Service Path
73
CWE
Product Name: FreeSSHd
Affected Version From: 1.3.1
Affected Version To: 1.3.1
Patch Exists: NO
Related CWE: N/A
CPE: a:freesshd:freesshd:1.3.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 (32-bit)
2020
FreeSSHd 1.3.1 – ‘FreeSSHDService’ Unquoted Service Path
A vulnerability exists in FreeSSHd 1.3.1 where the 'FreeSSHDService' service path is not quoted, allowing an attacker to gain elevated privileges on the system. This can be exploited by a local attacker to gain SYSTEM privileges.
Mitigation:
Ensure that all service paths are quoted to prevent attackers from exploiting this vulnerability.