vendor:
Sherpa Connector Service
by:
Manthan Chhabra, Harshit
7.8
CVSS
HIGH
Unquoted Service Path
428
CWE
Product Name: Sherpa Connector Service
Affected Version From: 2020.2.20328.2050
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2022-23909
CPE: a:gimmal:sherpa_connector_service:2020.2.20328.2050
Platforms Tested: Windows 10
2022
Sherpa Connector Service v2020.2.20328.2050 – Unquoted Service Path
Unquoted service path vulnerability in Sherpa Connector Service v2020.2.20328.2050 allows an attacker to escalate privileges by placing a malicious executable in the path of the service.
Mitigation:
Vendor has released a patch to address this vulnerability. Update to the latest version of Sherpa Connector Service.