vendor:
Program Access Controller
by:
Mohammed Alshehri
8.8
CVSS
HIGH
Unquoted Service Path
786
CWE
Product Name: Program Access Controller
Affected Version From: 1.2.0.0
Affected Version To: 1.2.0.0
Patch Exists: Yes
Related CWE: N/A
CPE: 2.3:a:gearbox_computers:program_access_controller:1.2.0.0:*:*:*:*:*:*
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Microsoft Windows 10 Education - 10.0.17763 N/A Build 17763
2020
Program Access Controller v1.2.0.0 – ‘PACService.exe’ Unquoted Service Path
This vulnerability could permit executing code during startup or reboot with the escalated privileges.
Mitigation:
The vendor has released a patch to address this vulnerability.