vendor:
HDD Health
by:
Jorge Manuel Lozano Gómez
7.2
CVSS
HIGH
Unquoted Service Path
835
CWE
Product Name: HDD Health
Affected Version From: 4.2.0.112
Affected Version To: 4.2.0.112
Patch Exists: NO
Related CWE:
CPE: a:panterasoft:hdd_health
Platforms Tested: Windows 11 64bit
2022
HDD Health 4.2.0.112 – ‘HDDHealth’ Unquoted Service Path
HDD Health installs a service with an unquoted service path. To properly exploit this vulnerability, the local attacker must insert an executable file in the path of the service. Upon service restart or system reboot, the malicious code will be run with elevated privileges.
Mitigation:
Ensure that all services have their paths enclosed within quotes.