vendor:
VUE Testing System
by:
Jok3r
7.8
CVSS
HIGH
Unquoted Service Path
426
CWE
Product Name: VUE Testing System
Affected Version From: 2.3.1911
Affected Version To: 2.3.1911
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Pro x64 es
2020
Pearson Vue VTS 2.3.1911 Installer – VUEApplicationWrapper Unquoted Service Path
The Application Wrapper is the component that automates the Pearson VUE Testing System. The Wrapper is a scheduler that runs in the background on the test center’s server. VUEApplicationWrapper service has an unquoted service path vulnerability and insecure file permissions on "Pearson VUE" directory that allows to overwrite by everyone so that unauthorized local user can leverage privileges to VUEService user that has administrative rights."
Mitigation:
Ensure that all services have a fully qualified path to the executable.