vendor:
SOUND4 Server
by:
LiquidWorm
7.2
CVSS
HIGH
Unquoted Search Path Issue
78
CWE
Product Name: SOUND4 Server
Affected Version From: 4.1.0102
Affected Version To: 4.1.0102
Patch Exists: NO
Related CWE:
CPE: a:sound4:sound4_server:4.1.102
Platforms Tested: Windows 10 Home 64 bit (build 9200)
2022
SOUND4 Server Service 4.1.102 – Local Privilege Escalation
The application suffers from an unquoted search path issue impacting the service 'SOUND4 Server' for Windows. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. A successful attempt would require the local user to be able to insert their code in the system root path undetected by the OS or other security applications where it could potentially be executed during application startup or reboot. If successful, the local user's code would execute with the elevated privileges of the application.
Mitigation:
Ensure that all applications are installed in a directory with a path that does not contain spaces or relative paths. Ensure that all applications are installed in a directory with a path that does not contain spaces or relative paths. Ensure that all applications are installed in a directory with a path that does not contain spaces or relative paths.