vendor:
Winstep Xtreme
by:
SamAlucard
5.5
CVSS
MEDIUM
Unquoted Service Path
428
CWE
Product Name: Winstep Xtreme
Affected Version From: 18.06.1996
Affected Version To: 18.06.1996
Patch Exists: NO
Related CWE:
CPE: a:winstep:xtreme:18.06.0096
Platforms Tested: Windows 7 Pro
2020
Winstep 18.06.0096 – ‘Xtreme Service’ Unquoted Service Path
The 'Winstep Xtreme Service' in Winstep 18.06.0096 has an unquoted service path vulnerability. This could allow an attacker to escalate privileges by placing a malicious executable in the path.
Mitigation:
To mitigate this vulnerability, the vendor should update the service to include quotes around the service path.