漏洞名称: Winpakpro 4.8 - 'ScheduleService' Unquoted Service Path EDB-ID: 49691 CVE: N/A 作者: ALAN MONDRAGON 类型: LOCAL 平台: WINDOWS 日期: 2021-03-22 易受攻击的应用程序: 未指定 发现者: Alan Mondragon 发现日期: 2021-03-16 厂商主页: https://www.security.honeywell.com/product-repository/winpak 软件链接: https://www.security.honeywell.com/product-repository/winpak WinPackPro 测试版本: 4.8 漏洞类型: Unquoted Service Path 测试操作系统: Windows 10 Pro 64 bits 发现未报价服务路径的步骤: 漏洞详细信息: A successful attempt would require the local user to be able to insert their code in the system root path undetected by the OS or other security applications where it could potentially be executed during application startup or reboot. If successful, the local user's code would execute with the elevated privileges of the application.