PT-2019-10051 · Winmagic · Winmagic Securedoc Disk Encryption
Publicado
2019-04-08
·
Atualizado
2019-04-24
·
CVE-2018-20341
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
WINMAGIC SecureDoc Disk Encryption software versions prior to 8.3
Description:
The issue allows an attacker to execute arbitrary code on a target system due to an Unquoted Service Path vulnerability. This occurs when the path to the application binary does not contain quotes, causing Windows to search for and potentially execute the binary in every folder of the specified path until it finds the executable.
Recommendations:
For versions prior to 8.3, update to version 8.3 or later to resolve the issue. As a temporary workaround, consider enclosing the executable path in quote tags to prevent Windows from searching for the binary in multiple folders.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Winmagic Securedoc Disk Encryption