Описание
Multiple NAS management applications provided by I-O DATA DEVICE, INC. register Windows services with unquoted file paths. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
EPSS
Процентиль: 4%
0.00019
Низкий
6.7 Medium
CVSS3
Дефекты
CWE-428
Связанные уязвимости
CVSS3: 6.7
github
4 месяца назад
NarSuS App registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
EPSS
Процентиль: 4%
0.00019
Низкий
6.7 Medium
CVSS3
Дефекты
CWE-428