header-logo
Suggest Exploit
vendor:
LiteManager
by:
Cakes
6.5
CVSS
MEDIUM
Unquoted Service Path
426
CWE
Product Name: LiteManager
Affected Version From: Mikogo 5.2.2.150317
Affected Version To: Mikogo 5.2.2.150317
Patch Exists: YES
Related CWE:
CPE: a:liteteam:litemanager:4.5.0
Metasploit:
Other Scripts:
Platforms Tested: Windows 10
2019

Mikogo 5.2.2.150317 – ‘Mikogo-Service’ Unquoted Serive Path

The Mikogo-Service in Mikogo 5.2.2.150317 allows local users to gain privileges via an unquoted service path vulnerability.

Mitigation:

Update to the latest version of Mikogo.
Source

Exploit-DB raw data:

# Exploit Title : Mikogo 5.2.2.150317 - 'Mikogo-Service' Unquoted Serive Path
# Date : 2019-10-15
# Exploit Author : Cakes
# Vendor: LiteManager Team
# Version : LiteManager 4.5.0
# Software: http://html.tucows.com/preview/518015/Mikogo?q=remote+support
# Tested on Windows 10
# CVE : N/A 


c:\>sc qc Mikogo-Service
[SC] QueryServiceConfig SUCCESS

SERVICE_NAME: Mikogo-Service
        TYPE               : 110  WIN32_OWN_PROCESS (interactive)
        START_TYPE         : 2   AUTO_START
        ERROR_CONTROL      : 1   NORMAL
        BINARY_PATH_NAME   : C:\Users\Administrator\AppData\Roaming\Mikogo\Mikogo-Service.exe
        LOAD_ORDER_GROUP   :
        TAG                : 0
        DISPLAY_NAME       : Mikogo-Service
        DEPENDENCIES       :
        SERVICE_START_NAME : LocalSystem