Description
CONTPAQi AdminPAQ 14.0.0 contains an unquoted service path vulnerability in the AppKeyLicenseServer service running with LocalSystem privileges. Attackers can exploit the unquoted path to inject malicious code in the service binary path, potentially executing arbitrary code with elevated system privileges during service startup.
Problem types
Unquoted Search Path or Element
Product status
Credits
Angel Canseco
References
www.exploit-db.com/exploits/50690 (ExploitDB-50690)
www.contpaqi.com/descargas (CONTPAQi Official Software Download Page)
www.vulncheck.com/...contpaqi-adminpaq-unquoted-service-path (VulnCheck Advisory: CONTPAQi® AdminPAQ 14.0.0 - Unquoted Service Path)