vendor:
ASUS InstantOn
by:
Cyril Vallicari
7,2
CVSS
HIGH
Privilege Escalation Unquoted Service Path
426
CWE
Product Name: ASUS InstantOn
Affected Version From: 2.3.1.1
Affected Version To: 2.3.1.1
Patch Exists: YES
Related CWE: N/A
CPE: a:asus:asus_instanton
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 x64 SP1
2016
InsOnSrv Asus InstantOn- Privilege Escalation Unquoted Service Path vulnerability
The application suffers from an unquoted service path issue impacting the service 'ASUS InstantOn (InsOnSrv.exe)' deployed as part of Asus InstantOn. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with system privileges.
Mitigation:
Ensure that all services have their paths quoted properly.