Description
Brother BRAdmin Professional 3.75 contains an unquoted service path vulnerability in the BRA_Scheduler service that allows local users to potentially execute arbitrary code. Attackers can place a malicious executable named 'BRAdmin' in the C:\Program Files (x86)\Brother\ directory to gain local system privileges.
Problem types
Unquoted Search Path or Element
Product status
Credits
Metin Yunus Kandemir
References
www.exploit-db.com/exploits/49671 (ExploitDB-49671)
global.brother/ (Brother Global Homepage)
support.brother.com/...3&dlid=dlf005042_000&flang=4&type3=26 (Brother Software Download Page)
docs.unsafe-inline.com/...ssional-3.75-unquoted-service-path (Vulnerability Technical Details)
www.vulncheck.com/...onal-brascheduler-unquoted-service-path (VulnCheck Advisory: BRAdmin Professional 3.75 - 'BRA_Scheduler' Unquoted Service Path)