Description
Acer Backup Manager 3.0.0.99 contains an unquoted service path vulnerability in the NTI IScheduleSvc service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\NTI\Acer Backup Manager\ to inject malicious executables that would run with elevated LocalSystem privileges.
Problem types
Unquoted Search Path or Element
Product status
Credits
Emmanuel Lujan
References
www.exploit-db.com/exploits/49889 (ExploitDB-49889)
www.acer.com/ac/en/US/content/home (Acer Official Homepage)
www.vulncheck.com/...e-ischedulesvcexe-unquoted-service-path (VulnCheck Advisory: Acer Backup Manager Module 3.0.0.99 - 'IScheduleSvc.exe' Unquoted Service Path)