Description
Acer Updater Service 1.2.3500.0 contains an unquoted service path vulnerability that allows local users to execute code with elevated system privileges. Attackers can exploit the unquoted path in C:\Program Files\Acer\Acer Updater\ to inject malicious executables that will run with LocalSystem permissions during service startup.
Problem types
Unquoted Search Path or Element
Product status
Credits
Emmanuel Lujan
References
www.exploit-db.com/exploits/49890 (ExploitDB-49890)
www.acer.com/ac/en/US/content/home (Acer Official Homepage)
www.vulncheck.com/...updaterserviceexe-unquoted-service-path (VulnCheck Advisory: Acer Updater Service 1.2.3500.0 - 'UpdaterService.exe' Unquoted Service Path)