Description
TotalAV 5.15.69 contains an unquoted service path vulnerability in multiple system services running with LocalSystem privileges. Attackers can place malicious executables in specific unquoted path segments to potentially gain SYSTEM-level access by exploiting the service path configuration.
Problem types
Unquoted Search Path or Element
Product status
Credits
Andrea Intilangelo
References
www.exploit-db.com/exploits/50314
www.exploit-db.com/exploits/50314 (ExploitDB-50314)
www.totalav.com (TotalAV Official Homepage)
www.vulncheck.com/advisories/totalav-unquoted-service-path (VulnCheck Advisory: TotalAV 5.15.69 - Unquoted Service Path)