Description
Splashtop 8.71.12001.0 contains an unquoted service path vulnerability in the Splashtop Software Updater Service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Splashtop\Splashtop Software Updater\ to inject malicious executables and escalate privileges.
Problem types
Unquoted Search Path or Element
Product status
Credits
A.I. hernandez
References
www.exploit-db.com/exploits/51182 (ExploitDB-51182)
www.splashtop.com (Splashtop Official Homepage)
www.vulncheck.com/advisories/splashtop-unquoted-service-path (VulnCheck Advisory: Splashtop 8.71.12001.0 - Unquoted Service Path)