Description
Flame II HSPA USB Modem contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Internet Telcel\ApplicationController.exe' to execute arbitrary code with elevated system privileges.
Problem types
Unquoted Search Path or Element
Product status
Credits
Ismael Nava
References
www.exploit-db.com/exploits/50708 (ExploitDB-50708)
web.archive.org/...personas/equipos/modems-usb/alcatel/x602a (Archived Telcel Flame II MODEM USB Product Page)
www.vulncheck.com/...lame-ii-modem-usb-unquoted-service-path (VulnCheck Advisory: FLAME II MODEM USB - Unquoted Service Path)