Advisories

BOOTP Turbo 2.0.0.1253 - 'bootpt.exe' Unquoted Service Path

Go Back
severity
high
date
Affecting
  • BOOTP Turbo 2.0.0.1253

CWE
  • CWE-428 Unquoted Search Path or Element
CVSS
8.5
CVSS V4 Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Credit
Erick Galindo
Description
BOOTP Turbo 2.0.0.1253 contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path to execute arbitrary code with elevated LocalSystem privileges during system startup or reboot.