Protegent Total Security 10.5.0.6 - Unquoted Service Path - CXSecurity.com

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1874807 漏洞类型
发布时间 2019-12-26 更新时间 2019-12-26
CVE编号 N/A CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2019120105
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
Title: Protegent Total Security 10.5.0.6 - Unquoted Service Path
Date: 2019-12-25
Author: Nir Yehoshua
Vendor: https://protegent360.com/
Product: https://protegent360.com/protegent-total-security.html
Tested on: Windows Windows 10 x64 [eng]


PoC:

C:\Users\nir>sc qc pgxsrv
[SC] QueryServiceConfig SUCCESS

SERVICE_NAME: pgxsrv
        TYPE               : 10  WIN32_OWN_PROCESS
        START_TYPE         : 2   AUTO_START
        ERROR_CONTROL      : 1   NORMAL
        BINARY_PATH_NAME   : C:\Program Files\Protegent TS\pgxsrv.exe
        LOAD_ORDER_GROUP   : UIGroup
        TAG                : 0
        DISPLAY_NAME       : Protegent Total Security Service
        DEPENDENCIES       :
        SERVICE_START_NAME : LocalSystem