Description
eBeam Interactive Suite 3.6 contains an unquoted service path vulnerability in the eBeam Stylus Driver service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Luidia\eBeam Stylus Driver\ to inject malicious executables that would run with LocalSystem permissions.
Problem types
Unquoted Search Path or Element
Product status
Credits
Luis Martinez
References
www.exploit-db.com/exploits/49648 (ExploitDB-49648)
esvc000385.wic045u.server-web.com/Downloads/eBeam/ (Software Download Page)
www.vulncheck.com/...eam-stylus-driver-unquoted-service-path (VulnCheck Advisory: eBeam Interactive Suite 3.6 - 'eBeam Stylus Driver' Unquoted Service Path)