Description
EPSON EasyMP Network Projection 2.81 contains an unquoted service path vulnerability in the EMP_NSWLSV service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\EPSON Projector\EasyMP Network Projection V2\ to inject malicious code that would execute with LocalSystem privileges.
Problem types
Unquoted Search Path or Element
Product status
Credits
Roberto Piña
References
www.exploit-db.com/exploits/48069 (ExploitDB-48069)
epson.com/...ort/easymp-network-projection-v2-86-for-windows (EPSON EasyMP Network Projection Support Page)
www.vulncheck.com/...jection-empnswlsv-unquoted-service-path (VulnCheck Advisory: EPSON EasyMP Network Projection 2.81 - 'EMP_NSWLSV' Unquoted Service Path)