Описание
EaseUS Data Recovery 15.1.0.0 contains an unquoted service path vulnerability in the EaseUS UPDATE SERVICE executable. Attackers can exploit the unquoted path to inject and execute malicious code with elevated LocalSystem privileges.
EPSS
Процентиль: 2%
0.00013
Низкий
8.4 High
CVSS3
Дефекты
CWE-428
Связанные уязвимости
CVSS3: 8.4
github
25 дней назад
EaseUS Data Recovery 15.1.0.0 contains an unquoted service path vulnerability in the EaseUS UPDATE SERVICE executable. Attackers can exploit the unquoted path to inject and execute malicious code with elevated LocalSystem privileges.
EPSS
Процентиль: 2%
0.00013
Низкий
8.4 High
CVSS3
Дефекты
CWE-428