Description
PDF Complete 3.5.310.2002 contains an unquoted service path vulnerability in its pdfsvc.exe service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with elevated LocalSystem privileges.
Problem types
Unquoted Search Path or Element
Product status
Credits
Zaira Alquicira
References
www.exploit-db.com/exploits/49226 (ExploitDB-49226)
pdf-complete.informer.com/3.5/ (PDF Complete Vendor Homepage)
www.vulncheck.com/...omplete-pdfsvcexe-unquoted-service-path (VulnCheck Advisory: PDF Complete 3.5.310.2002 - 'pdfsvc.exe' Unquoted Service Path)