Description
MiniTool ShadowMaker 3.2 contains an unquoted service path vulnerability in the MTAgentService that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\MiniTool ShadowMaker\AgentService.exe' to inject malicious executables and escalate privileges.
Problem types
Unquoted Search Path or Element
Product status
Credits
Thalia Nieto
References
www.exploit-db.com/exploits/49336 (ExploitDB-49336)
www.minitool.com (Vendor Homepage)
www.vulncheck.com/...er-mtagentservice-unquoted-service-path (VulnCheck Advisory: MiniTool ShadowMaker 3.2 - 'MTAgentService' Unquoted Service Path)