vendor:
Windows Firewall Control
by:
zaeek@protonmail.com
5.5
CVSS
MEDIUM
Privilege Escalation
426
CWE
Product Name: Windows Firewall Control
Affected Version From: 4.8.6.0
Affected Version To: 4.8.6.0
Patch Exists: NO
Related CWE:
CPE: a:binisoft:windows_firewall_control:4.8.6.0
Platforms Tested: Windows 7 32/64bit
2016
Windows Firewall Control Unquoted Service Path Privilege Escalation
Windows Firewall Control lacks quotes in filepath, allowing a potential vector of privilege escalation attack. The local attacker can insert an executable file in the path of the service, which will be run with elevated privileges upon service restart or system reboot.
Mitigation:
The vendor should update Windows Firewall Control to include quotes in the filepath to prevent unquoted service path vulnerabilities. Users should update to the latest version of Windows Firewall Control.