Description
Mikogo 5.2.2.150317 contains an unquoted service path vulnerability in the Mikogo-Service Windows service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with LocalSystem privileges by placing executable files in specific path locations.
Problem types
Unquoted Search Path or Element
Product status
Credits
Cakes
References
www.exploit-db.com/exploits/47510 (ExploitDB-47510)
html.tucows.com/preview/518015/Mikogo?q=remote+support (Mikogo Software Download Page)
www.vulncheck.com/...go-mikogo-service-unquoted-service-path (VulnCheck Advisory: Mikogo 5.2.2.150317 - 'Mikogo-Service' Unquoted Service Path)