vendor:
Genie
by:
Tulpa
5.5
CVSS
MEDIUM
Unquoted Service Path Elevation of Privilege
426
CWE
Product Name: Genie
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:netgear:genie:2.4.32
Platforms Tested: Windows 7 x86
2016
Netgear Genie 2.4.32 Unquoted Service Path Elevation of Privilege
Netgear Genie installs a service called 'NETGEARGenieDaemon' with an unquoted service path running with SYSTEM privileges. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system.
Mitigation:
To mitigate this vulnerability, the vendor should update the installation process to ensure that the service path is quoted correctly. Users should also ensure that they are running the latest version of the software and apply any patches or updates provided by the vendor.