vendor:
Management and Security Application
by:
Metin Yunus Kandemir
7.2
CVSS
HIGH
Unquoted Service Path Privilege Escalation
78
CWE
Product Name: Management and Security Application
Affected Version From: v5.2
Affected Version To: v5.2
Patch Exists: NO
Related CWE: N/A
CPE: a:intel:management_and_security_application
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7
2020
Intel(r) Management and Security Application 5.2 – User Notification Service Unquoted Service Path
An attacker with low privileges can download a malicious executable file to the Intel directory and set it to run with the unquoted service path of the Intel User Notification Service. After the system is rebooted, the malicious executable will be executed with SYSTEM privileges.
Mitigation:
Ensure that all services have their paths quoted and that all services are running with the least privileges necessary.