Description
Realtek Wireless LAN Utility 700.1631 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted service path by inserting malicious code in the system root path that would execute during application startup or system reboot.
Problem types
Unquoted Search Path or Element
Product status
Credits
Luis Martinez
References
www.exploit-db.com/exploits/49646 (ExploitDB-49646)
www.realtek.com/en/ (Realtek Official Homepage)
www.vulncheck.com/...tility-realteknsu-unquoted-service-path (VulnCheck Advisory: Realtek Wireless LAN Utility 700.1631 - 'Realtek11nSU' Unquoted Service Path)