Advisories

Wondershare Driver Install Service help 10.7.1.321 - 'ElevationService' Unquote Service Path

Go Back
severity
high
date
Affecting
  • Wondershare Driver Install Service help 10.7.1.321

CWE
  • CWE-428 Unquoted Search Path or Element
CVSS
8.5
CVSS V4 Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Credit
Luis Sandoval
Description
Wondershare Driver Install Service contains an unquoted service path vulnerability in the ElevationService executable that allows local attackers to potentially inject malicious code. Attackers can exploit the unquoted path to replace the service binary with a malicious executable, enabling privilege escalation to LocalSystem account.