Description
EaseUS Data Recovery 15.1.0.0 contains an unquoted service path vulnerability in the EaseUS UPDATE SERVICE executable. Attackers can exploit the unquoted path to inject and execute malicious code with elevated LocalSystem privileges.
Problem types
Unquoted Search Path or Element
Product status
Credits
bios
References
www.exploit-db.com/exploits/50886 (ExploitDB-50886)
www.easeus.com/ (EaseUS Official Homepage)
www.vulncheck.com/...very-ensserverexe-unquoted-service-path (VulnCheck Advisory: EaseUS Data Recovery - 'ensserver.exe' Unquoted Service Path)