vendor:
NetDrive
by:
Tulpa
7,2
CVSS
HIGH
Unquoted Service Path Elevation of Privilege
426
CWE
Product Name: NetDrive
Affected Version From: 2.6.12
Affected Version To: 2.6.12
Patch Exists: NO
Related CWE: N/A
CPE: a:netdrive:netdrive:2.6.12
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 x86
2016
NetDrive 2.6.12 Unquoted Service Path Elevation of Privilege
NetDrive installs a service with an unquoted service path running with SYSTEM privileges. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system.
Mitigation:
Ensure that all services have a fully qualified path to the executable.