Advisories

CoolerMaster MasterPlus 1.8.5 - 'MPService' Unquoted Service Path

Go Back
severity
high
date
Affecting
  • Cooler Master MasterPlus 1.8.5

CWE
  • CWE-427 Uncontrolled Search Path Element
CVSS
8.5
CVSS V4 Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Credit
Damian Semon Jr (Blue Team Alpha)
Description
CoolerMaster MasterPlus 1.8.5 contains an unquoted service path vulnerability in the MPService that allows local attackers to execute code with elevated system privileges. Attackers can drop a malicious executable in the service path and trigger code execution during service startup or system reboot.