Description
Mediconta 3.7.27 contains an unquoted service path vulnerability in the servermedicontservice that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\medicont3\ to inject malicious code that would execute with LocalSystem permissions during service startup.
Problem types
Unquoted Search Path or Element
Product status
Credits
Luis Martinez
References
www.exploit-db.com/exploits/51064 (ExploitDB-51064)
www.infonetsoftware.com (Vendor Homepage)
www.vulncheck.com/...ermedicontservice-unquoted-service-path (VulnCheck Advisory: Mediconta 3.7.27 - 'servermedicontservice' Unquoted Service Path)