Description
Advanced System Care Service 13.0.0.157 contains an unquoted service path vulnerability in the AdvancedSystemCareService13 service binary path that allows local attackers to escalate privileges. Attackers can place malicious executables in the system root path that will be executed with LocalSystem privileges during service startup or system reboot.
Problem types
Unquoted Search Path or Element
Product status
Credits
Jair Amezcua
References
www.exploit-db.com/exploits/49049 (ExploitDB-49049)
www.iobit.com (Official Product Homepage)
www.iobit.com/es/advancedsystemcarepro.php (Product Reference)
www.vulncheck.com/...uoted-service-path-privilege-escalation (VulnCheck Advisory: Advanced System Care Service 13.0.0.157 Unquoted Service Path Privilege Escalation)