vendor:
Advanced SystemCare
by:
Ashiyane Digital Security Team
7.5
CVSS
HIGH
Unquoted Service Path Privilege Escalation
428
CWE
Product Name: Advanced SystemCare
Affected Version From: All versions prior to 10.0.2
Affected Version To: 10.0.2
Patch Exists: NO
Related CWE:
CPE: a:iobit:advanced_systemcare
Platforms Tested: Windows 7
2016
IObit Advanced SystemCare Unquoted Service Path Privilege Escalation
IObit Advanced SystemCare installs a service with an unquoted service path. To exploit this vulnerability, the attacker needs to insert an executable file in the path of the service. Upon service restart or system reboot, the malicious code will be run with elevated privileges.
Mitigation:
The vendor should update the software to ensure that the service path is quoted correctly. Users should also regularly update their software to the latest version.