Description
MacPaw Encrypto 1.0.1 contains an unquoted service path vulnerability in its Encrypto Service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files\Encrypto\ to inject malicious executables and escalate privileges on Windows systems.
Problem types
Unquoted Search Path or Element
Product status
Credits
Ismael Nava
References
www.exploit-db.com/exploits/49694 (ExploitDB-49694)
macpaw.com/encrypto (MacPaw Encrypto Official Homepage)
www.vulncheck.com/...-encrypto-service-unquoted-service-path (VulnCheck Advisory: MacPaw Encrypto 1.0.1 - 'Encrypto Service' Unquoted Service Path)