vendor:
OCS Inventory NG Windows Agent
by:
msd0pe
7.4
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: OCS Inventory NG Windows Agent
Affected Version From: 2.3.0.0
Affected Version To: 2.3.1.0
Patch Exists: YES
Related CWE:
CPE: a:ocs_inventory-ng:ocs_inventory_ng_windows_agent
Platforms Tested: Windows
2023
OCS Inventory NG 2.3.0.0 – Unquoted Service Path
OCS Inventory NG Windows Agent versions below 2.3.1.0 contains an unquoted service path which allows attackers to escalate privileges to the system level. An attacker can find the unquoted service path using the wmic command, get informations about the service using the sc qc command, generate a reverse shell using the msfvenom command, upload the reverse shell to the vulnerable system, start a listener, and reboot the service/server to gain system level privileges.
Mitigation:
Upgrade to OCS Inventory NG Windows Agent version 2.3.1.0 or later.