vendor:
Game Jackal Server
by:
Idan Malihi
7.5
CVSS
HIGH
Unquoted Service Path
428
CWE
Product Name: Game Jackal Server
Affected Version From: 5
Affected Version To: 5
Patch Exists: NO
Related CWE: CVE-2023-36166
CPE: a:allradiosoft:game_jackal_server:5
Platforms Tested: Microsoft Windows 10 Pro
2023
Game Jackal Server v5 – Unquoted Service Path
The Game Jackal Server v5 software on Windows 10 Pro has an unquoted service path vulnerability, which allows local attackers to gain elevated privileges via a Trojan horse executable file in the %SYSTEMDRIVE% folder.
Mitigation:
The vendor has not provided a patch for this vulnerability. To mitigate the risk, users can manually update the service path to include quotes around the executable file path.