Description
BlueStacks App Player 2.4.44.62.57 contains an unquoted service path vulnerability in the BstHdLogRotatorSvc service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe to inject malicious executables and escalate privileges.
Problem types
Unquoted Search Path or Element
Product status
Credits
Diego Armando Buztamante Rico
References
www.exploit-db.com/exploits/47582 (ExploitDB-47582)
/www.bluestacks.com (Official Product Homepage)
www.vulncheck.com/...bsthdlogrotatorsvc-unquote-service-path (VulnCheck Advisory: Blue Stacks App Player 2.4.44.62.57 - "BstHdLogRotatorSvc" Unquote Service Path)