Skip to content
Threat Feed

Tag

Unquoted Service Path

13 briefs RSS
high advisory

CVE-2016-20095: Matrix42 Remote Control Host Unquoted Service Path Privilege Escalation

A local attacker can exploit CVE-2016-20095, an unquoted service path vulnerability in Matrix42 Remote Control Host version 3.20.0031, to achieve arbitrary code execution with SYSTEM privileges by placing a malicious executable named 'Program.exe' in the 'C:\Program Files\' directory, leading to privilege escalation when the vulnerable service starts.

Matrix42 Remote Control Host 3.20.0031 privilege-escalation unquoted-service-path windows matrix42
2r 2t 1c
high advisory

CVE-2016-20089: Iperius Remote Unquoted Service Path Vulnerability

An unquoted service path vulnerability, CVE-2016-20089, in Iperius Remote version 1.7.0 allows a local attacker to execute arbitrary code with SYSTEM privileges by placing a malicious executable in a specific directory when the legitimate service path contains spaces, enabling privilege escalation upon service restart or system reboot.

Iperius Remote 1.7.0 privilege-escalation windows vulnerability unquoted-service-path
2r 1t 4i
medium threat

Lenovo LegionSpace 1.7.11.2 Unquoted Service Path Vulnerability

A local exploit has been published for Lenovo LegionSpace 1.7.11.2, detailing an Unquoted Service Path vulnerability in the 'DAService', potentially leading to local privilege escalation.

LegionSpace unquoted-service-path privilege-escalation windows
2r 1t
high advisory

VX Search Unquoted Service Path Privilege Escalation (CVE-2021-47974)

VX Search 13.5.28 is vulnerable to an unquoted service path vulnerability (CVE-2021-47974) in both VX Search Server and VX Search Enterprise services, allowing local attackers to escalate privileges by placing malicious executables in unquoted path directories.

VX Search +2 privilege-escalation unquoted service path cve-2021-47974
2r 1t 1c
high threat

Kite Unquoted Service Path Vulnerability (CVE-2020-37247)

Kite 4.2.0.1 U1 contains an unquoted service path vulnerability (CVE-2020-37247) in the KiteService Windows service that allows local attackers to escalate privileges by placing a malicious executable in a directory due to the unquoted service path.

Kite 4.2.0.1 U1 privilege-escalation unquoted service path cve-2020-37247 windows
2r 1t 1c
high advisory

CVE-2020-37232 - Advanced System Care Unquoted Service Path Vulnerability

Advanced System Care Service 13.0.0.157 suffers from an unquoted service path vulnerability allowing local attackers to escalate privileges by placing a malicious executable in the system root path.

Advanced System Care Service privilege-escalation unquoted service path cve-2020-37232
2r 1t 1c
high advisory

Privacy Drive 3.17.0 Unquoted Service Path Privilege Escalation (CVE-2020-37231)

Privacy Drive 3.17.0 contains an unquoted service path vulnerability in the pdsvc.exe service, allowing local attackers to escalate privileges by placing malicious executables in the unquoted path directories, leading to arbitrary code execution with LocalSystem privileges.

Privacy Drive 3.17.0 privilege escalation unquoted service path cve-2020-37231
2r 1t 1c
high threat

Syncplify.me Server! Unquoted Service Path Vulnerability (CVE-2020-37230)

Syncplify.me Server! version 5.0.37 contains an unquoted service path vulnerability (CVE-2020-37230) in the SMWebRestServicev5 service, allowing a local attacker to escalate privileges by placing a malicious executable in the service path.

Syncplify.me Server! 5.0.37 unquoted-service-path privilege-escalation windows
2r 1t 1c
high advisory

OKI sPSV Port Manager Unquoted Service Path Vulnerability (CVE-2020-37229)

OKI sPSV Port Manager 1.0.41 contains an unquoted service path vulnerability in the sPSVOpLclSrv service, allowing local attackers to escalate privileges by inserting executable files into the unquoted path.

sPSV Port Manager 1.0.41 privilege-escalation unquoted service path cve-2020-37229 windows
2r 2t 1c
high advisory

CVE-2020-37223 - IObit Uninstaller Unquoted Service Path Privilege Escalation

IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service, allowing local attackers to escalate privileges to SYSTEM by placing a malicious executable in the service's path.

Uninstaller 9.5.0.15 privilege-escalation unquoted service path cve-2020-37223
2r 1t 1c
high advisory

Argus Surveillance DVR Unquoted Service Path Vulnerability (CVE-2021-47945)

Argus Surveillance DVR 4.0 contains an unquoted service path vulnerability in the DVRWatchdog service (CVE-2021-47945), enabling local attackers to escalate privileges by placing a malicious executable in the Program Files directory to be executed as LocalSystem.

Surveillance DVR 4.0 unquoted-service-path privilege-escalation windows
2r 1t 1c
high advisory

Sheed AntiVirus Unquoted Service Path Privilege Escalation (CVE-2016-20061)

Sheed AntiVirus 2.3 contains an unquoted service path vulnerability in the ShavProt service that allows local attackers to escalate privileges by placing a malicious executable in the unquoted path, leading to arbitrary code execution as LocalSystem.

privilege-escalation unquoted-service-path cve-2016-20061
2r 1t 1c 1i
low advisory

Potential Exploitation of an Unquoted Service Path Vulnerability

This rule detects potential exploitation of unquoted service path vulnerabilities, where adversaries may escalate privileges by placing a malicious executable in a higher-level directory within the path of an unquoted service executable.

Microsoft Defender XDR +4 privilege-escalation unquoted-service-path windows
2r 1t