vendor:
TotalAV
by:
Andrea Intilangelo
7,8
CVSS
HIGH
Unquoted Service Path
428
CWE
Product Name: TotalAV
Affected Version From: 5.15.69
Affected Version To: 5.15.69
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 10 Pro 20H2 and 21H1 x64
2021
TotalAV 5.15.69 – Unquoted Service Path
The PC Security Management Service, PC Security Management Monitoring Service, and Anti-Malware SDK Protected Service services from TotalAV version 5.15.69 are affected by unquoted service path (CWE-428) vulnerability which may allow a user to gain SYSTEM privileges since they all running with higher privileges. To exploit the vulnerability is possible to place executable(s) following the path of the unquoted string.
Mitigation:
Ensure that all services are running with the least privileges required and that all paths are quoted.