vendor:
SugarSync
by:
Jorge Manuel Lozano Gómez
8.8
CVSS
HIGH
Unquoted Service Path
CWE
Product Name: SugarSync
Affected Version From: 4.1.2003
Affected Version To: 4.1.2003
Patch Exists: NO
Related CWE:
CPE: a:sugarsync:sugarsync:4.1.3
Platforms Tested: Windows 11 64bit
2022
SugarSync 4.1.3 – ‘SugarSync Service’ Unquoted Service Path
SugarSync installs a service with an unquoted service path. To properly exploit this vulnerability, the local attacker must insert an executable file in the path of the service. Upon service restart or system reboot, the malicious code will be run with elevated privileges.
Mitigation:
Enclose the service path within quotes.