Description
Quick 'n Easy FTP Service 3.2 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code during service startup. Attackers can exploit the misconfigured service binary path to inject malicious executables with elevated LocalSystem privileges during system boot or service restart.
Problem types
Unquoted Search Path or Element
Product status
Credits
yunaranyancat
References
www.exploit-db.com/exploits/48983 (ExploitDB-48983)
www.pablosoftwaresolutions.com/...k__n_easy_ftp_service.html (Vendor Homepage)
www.pablosoftwaresolutions.com/download.php?id=10 (Software Download Page)
www.vulncheck.com/...-easy-ftp-service-unquoted-service-path (VulnCheck Advisory: Quick 'n Easy FTP Service 3.2 - Unquoted Service Path)