Description
ShareMouse 5.0.43 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the insecure service path configuration by placing malicious executables in specific system directories to gain elevated access during service startup.
Problem types
Unquoted Search Path or Element
Product status
Credits
Alan Lacerda (alacerda)
References
www.exploit-db.com/exploits/48794 (ExploitDB-48794)
www.sharemouse.com/ (ShareMouse Official Vendor Homepage)
www.vulncheck.com/...haremouse-service-unquoted-service-path (VulnCheck Advisory: ShareMouse 5.0.43 - 'ShareMouse Service' Unquoted Service Path)