Description
WifiHotSpot 1.0.0.0 contains an unquoted service path vulnerability in its WifiHotSpotService.exe that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path during system startup or reboot to inject and run malicious executables with LocalSystem permissions.
Problem types
Unquoted Search Path or Element
Product status
Credits
Erick Galindo
References
www.exploit-db.com/exploits/49845 (ExploitDB-49845)
wifi-hotspot.gearboxcomputers.com/ (WiFi Hotspot Product Page)
www.vulncheck.com/...hotspotserviceexe-unquoted-service-path (VulnCheck Advisory: WifiHotSpot 1.0.0.0 - 'WifiHotSpotService.exe' Unquoted Service Path)