Description
Pingzapper 2.3.1 contains an unquoted service path vulnerability in the PingzapperSvc service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Pingzapper\PZService.exe' to inject malicious executables and escalate privileges.
Problem types
Unquoted Search Path or Element
Product status
Credits
Brian Rodriguez
References
www.exploit-db.com/exploits/49626 (ExploitDB-49626)
pingzapper.com (Vendor Homepage)
pingzapper.com/download (Software Download Page)
www.vulncheck.com/...per-pingzappersvc-unquoted-service-path (VulnCheck Advisory: Pingzapper 2.3.1 - 'PingzapperSvc' Unquoted Service Path)