vendor:
iDeskService
by:
Leslie Lara
5.5
CVSS
MEDIUM
Unquoted Service Path
428
CWE
Product Name: iDeskService
Affected Version From: 3.0.2.1
Affected Version To: 3.0.2.1
Patch Exists: NO
Related CWE:
CPE: a:ideskservice:ideskservice:3.0.2.1
Platforms Tested: Windows 10 Pro 64 bits
2020
iDeskService 3.0.2.1 – ‘iDeskService’ Unquoted Service Path
The iDeskService version 3.0.2.1 is vulnerable to an unquoted service path vulnerability. This vulnerability allows an attacker to escalate privileges by placing a malicious executable in a directory higher in the system's PATH environment variable.
Mitigation:
To mitigate this vulnerability, the vendor should update the software to use quoted paths for service binaries. Users should also ensure that they have the latest version of the software installed.